logo

CVE-2024-38213: Copy2Pwn Exploit Evades Windows Web Protections

ID: 5eab82f4-a090-5eb3-912d-74c73ae419ca

STIX ID: report--5eab82f4-a090-5eb3-912d-74c73ae419ca

Feed Name: Zero Day Initiative (ZDI) Blog

Threat Score
80/100

Date Published: 2024-08-15

Date Updated: 2026-05-01

Author: Peter Girnus

...
...

In March 2024, Trend Micro’s Zero Day Initiative investigated a DarkGate campaign and discovered CVE-2024-38213 — dubbed copy2pwn — a vulnerability that allows files copied from WebDAV shares to bypass Windows mark-of-the-web protections and enable remote code execution; the issue was reported to Microsoft and patched in June 2024.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.