CVE-2024-21412

high

Description

Internet Shortcut Files Security Feature Bypass Vulnerability

References

https://thehackernews.com/2024/06/darkgate-malware-replaces-autoit-with.html

https://securelist.com/vulnerability-report-q1-2024/112554/

https://therecord.media/kev-list-vulnerabilities-patched-significantly-faster?&web_view=true

https://cyware.com/news/darkgate-campaign-leverages-windows-smartscreen-bypass-flaw-77934b29/?&web_view=true

https://www.trendmicro.com/en_us/research/24/c/cve-2024-21412--darkgate-operators-exploit-microsoft-windows-sma.html?&web_view=true

https://www.bleepingcomputer.com/news/security/hackers-exploit-windows-smartscreen-flaw-to-drop-darkgate-malware/

https://www.trendmicro.com/en_us/research/24/c/cve-2024-21412--darkgate-operators-exploit-microsoft-windows-sma.html

https://www.hivepro.com/threat-advisory/water-hydra-exploits-cve-2024-21412-to-target-financial-traders/

https://securityaffairs.com/159171/hacking/cisa-adds-windows-bugs-known-exploited-vulnerabilities-catalog.html?web_view=true

https://www.hivepro.com/threat-advisory/microsofts-february-2024-patch-tuesday-addresses-two-zero-day-vulnerabilities/

https://securityaffairs.com/159171/hacking/cisa-adds-windows-bugs-known-exploited-vulnerabilities-catalog.html

https://www.infosecurity-magazine.com/news/water-hydras-zero-day-financial/?&web_view=true

https://www.darkreading.com/vulnerabilities-threats/attackers-exploit-microsoft-security-bypass-zero-day-bugs?&web_view=true

https://securityaffairs.com/159106/security/microsoft-patch-tuesday-for-february-2024.html

https://www.theregister.com/2024/02/14/patch_tuesday_feb_2024/

https://www.trendmicro.com/en_us/research/24/b/cve202421412-water-hydra-targets-traders-with-windows-defender-s.html

https://www.bleepingcomputer.com/news/security/hackers-used-new-windows-defender-zero-day-to-drop-darkme-malware/

https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-21412

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21412

Details

Source: Mitre, NVD

Published: 2024-02-13

Updated: 2024-06-11

Risk Information

CVSS v2

Base Score: 9.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:N

Severity: High

CVSS v3

Base Score: 8.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

Severity: High