logo

Microsoft fixes Windows Smart App Control zero-day exploited since 2018

ID: a4fcb3e9-3629-58cb-9e77-7cca47f38a33

STIX ID: report--a4fcb3e9-3629-58cb-9e77-7cca47f38a33

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-09-10

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Microsoft patched CVE-2024-38217—an LNK ‘stomping’ weakness exploited since at least 2018 that can remove Mark of the Web from downloaded files and bypass Smart App Control/SmartScreen protections—after Elastic Security Labs publicly disclosed the issue and researchers found historical samples on VirusTotal; Microsoft published an advisory and related mitigation details.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.