A AegiFlow
UNKNOWNKNOWN EXPLOITED

CVE-2024-29988

Microsoft SmartScreen Prompt Security Feature Bypass Vulnerability

Published
2024-04-30
Modified
2026-07-31
Sources
cisa-kev

Summary

Microsoft SmartScreen Prompt contains a security feature bypass vulnerability that allows an attacker to bypass the Mark of the Web (MotW) feature. This vulnerability can be chained with CVE-2023-38831 and CVE-2024-21412 to execute a malicious file.

References

Includes data from the CISA Known Exploited Vulnerabilities catalog.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.