Exploitation Summary
CVE-2024-38213 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added August 13, 2024.
Description
Windows Mark of the Web Security Feature Bypass Vulnerability
References (2)
Core 2
Core References
US Government Resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-38213
Patch, Vendor Advisory vendor-advisory
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38213
Scores
CVSS v3
6.5
EPSS
0.1337
EPSS Percentile
95.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
active
Automatable
no
Technical Impact
partial
Details
CISA KEV
2024-08-13
VulnCheck KEV
2024-08-13
InTheWild.io
2024-08-13
ENISA EUVD
EUVD-2024-37180
CWE
CWE-693
Status
published
Products (14)
microsoft/windows_10_1507
< 10.0.10240.20680
microsoft/windows_10_1607
< 10.0.14393.7070
microsoft/windows_10_1809
< 10.0.17763.5936
microsoft/windows_10_21h2
< 10.0.19044.4529
microsoft/windows_10_22h2
< 10.0.19045.4529
microsoft/windows_11_21h2
< 10.0.22000.3019
microsoft/windows_11_22h2
< 10.0.22621.3737
microsoft/windows_11_23h2
< 10.0.22631.3737
microsoft/windows_server_2012
r2
microsoft/windows_server_2012
< 6.2.9200.24919
... and 4 more
Published
Aug 13, 2024
KEV Added
Aug 13, 2024
Tracked Since
Feb 18, 2026