← Back to browse · API

CVE-2024-38213

Severity
MEDIUM
CVSS
6.5
EPSS
0.13626
Risk score
55.77
CISA KEV
Yes
PoC
No
Published
2024-08-13
Modified
2024-08-13
First seen
2026-08-07
Aliases
EUVD-2024-37180, GHSA-X6J5-WVPJ-P4QV
Products
Microsoft:Windows, Microsoft:Windows 10 Version 1507 10.0.10240.0 <10.0.10240.20680, Microsoft:Windows 10 Version 1607 10.0.14393.0 <10.0.14393.7070, Microsoft:Windows 10 Version 1809 10.0.17763.0 <10.0.17763.5936, Microsoft:Windows 10 Version 21H2 10.0.19043.0 <10.0.19044.4529, Microsoft:Windows 10 Version 22H2 10.0.19045.0 <10.0.19045.4529, Microsoft:Windows 11 Version 23H2 10.0.22631.0 <10.0.22631.3737, Microsoft:Windows 11 version 21H2 10.0.0 <10.0.22000.3019, Microsoft:Windows 11 version 22H2 10.0.22621.0 <10.0.22621.3737, Microsoft:Windows 11 version 22H3 10.0.22631.0 <10.0.22631.3737, Microsoft:Windows Server 2012 (Server Core installation) 6.2.9200.0 <6.2.9200.24919, Microsoft:Windows Server 2012 6.2.9200.0 <6.2.9200.24919, Microsoft:Windows Server 2012 R2 (Server Core installation) 6.3.9600.0 <6.3.9600.22023, Microsoft:Windows Server 2012 R2 6.3.9600.0 <6.3.9600.22023, Microsoft:Windows Server 2016 (Server Core installation) 10.0.14393.0 <10.0.14393.7070, Microsoft:Windows Server 2016 10.0.14393.0 <10.0.14393.7070, Microsoft:Windows Server 2019 (Server Core installation) 10.0.17763.0 <10.0.17763.5936, Microsoft:Windows Server 2019 10.0.17763.0 <10.0.17763.5936, Microsoft:Windows Server 2022 10.0.20348.0 <10.0.20348.2527, Microsoft:Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.0 <10.0.25398.950
Sources
euvd EUVD-2024-37180
cisa.gov CVE-2024-38213

Description

Microsoft Windows SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the SmartScreen user experience via a malicious file.

References