Record summary

CVE-2023-36025 has a selected CVSS score of 8.8 (high); EIP currently links 3 repository PoCs. CISA lists CVE-2023-36025 in KEV; VulnCheck reports CVE-2023-36025 use in known ransomware campaigns.

Description

Windows SmartScreen Security Feature Bypass Vulnerability

Description source: GitHub Advisory

Exploitation context

Known exploitation

CISA KEV
Listed · Nov 14, 2023 · CISA
VulnCheck KEV
Listed · Nov 14, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck
Ransomware use
Observed · VulnCheck

Available material

Repository PoCs
3

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 7, 2025 · Source: CVE List

Affected products and versions

Showing 12 of 24
ProductSourceVersion rangeStatus
CISAVersion data not supplied
CVE List10.0.10240.0 to < 10.0.10240.20308affected
CVE List10.0.14393.0 to < 10.0.14393.6452affected
CVE List10.0.17763.0 to < 10.0.17763.5122affected
10.0.0 to < 10.0.17763.5122affected
CVE List10.0.19043.0 to < 10.0.19043.3693affected
CVE List10.0.19045.0 to < 10.0.19045.3693affected
CVE List10.0.22631.0 to < 10.0.22631.2715affected
CVE List10.0.0 to < 10.0.22000.2600affected
CVE List10.0.22621.0 to < 10.0.22621.2715affected
CVE List10.0.22631.0 to < 10.0.22631.2715affected
CVE List6.0.6003.0 to < 6.0.6003.22367affected
CVE List6.1.7601.0 to < 6.1.7601.26816affected

Proofs of concept

3

Repository PoCs

GitHubka7ana/CVE-2023-36025Repository PoCby ka7anaStars: 13Not analyzed3 files

533 B · linked to 2 vulnerabilities

GitHub

PoC details
GitHubJ466Y/test_CVE-2023-36025Repository PoCby J466YStars: 5Not analyzed2 files

130 B

GitHub

PoC details
GitHubcoolman6942o/-EXPLOIT-CVE-2023-36025Repository PoCby coolman6942oStars: 5Not analyzed3 files

1.2 KiB

GitHub

PoC details

References

3