CVE-2024-38213

MEDIUM KEV

Windows Mark of the Web - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2024-38213 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added August 13, 2024.

Description

Windows Mark of the Web Security Feature Bypass Vulnerability

References (2)

Core 2

Scores

CVSS v3 6.5
EPSS 0.1337
EPSS Percentile 95.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact partial

Details

CISA KEV 2024-08-13
VulnCheck KEV 2024-08-13
InTheWild.io 2024-08-13
ENISA EUVD EUVD-2024-37180
CWE
CWE-693
Status published
Products (14)
microsoft/windows_10_1507 < 10.0.10240.20680
microsoft/windows_10_1607 < 10.0.14393.7070
microsoft/windows_10_1809 < 10.0.17763.5936
microsoft/windows_10_21h2 < 10.0.19044.4529
microsoft/windows_10_22h2 < 10.0.19045.4529
microsoft/windows_11_21h2 < 10.0.22000.3019
microsoft/windows_11_22h2 < 10.0.22621.3737
microsoft/windows_11_23h2 < 10.0.22631.3737
microsoft/windows_server_2012 r2
microsoft/windows_server_2012 < 6.2.9200.24919
... and 4 more
Published Aug 13, 2024
KEV Added Aug 13, 2024
Tracked Since Feb 18, 2026