CVE-2023-36025Active Exploitation(microsoft / windows_10_1507)

MEDIUMCVSS 8.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for microsoft windows_10_1507 systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Windows SmartScreen Security Feature Bypass Vulnerability

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2023-12-05. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1507
  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-10); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
windows_10_1507windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_21h2windows_11_22h2windows_11_23h2windows_server_2008windows_server_2012

2 versions affected across 13 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-10: 1Mentions · 2026-05-25: 1Active Exploitation · 2026-04-10: 104-1005-25
Signal classification2 categories
Active Exploitation
150.0%
General
150.0%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-04-101
Active Exploitation1
2026-05-251
General1
Full discourse2 posts
  • Giuseppe `N3mes1s`@N3mes1s
    Active Exploitation

    Seems that the "Actor" has stuff around from a previous campaign with the CVE-2023-36025 .url shortcut exploits Funny enough it was showing LiteLLM installation (anyone? :D ) https://gist.github.com/N3mes1s/b5b0b96782b9f832819d2db7c6684f84#appendix-b-live-infrastructure--earlier-campaign-analysis https://t.co/bYZSj4FoPC

    Post summary

    The tweet indicates that an adversary is actively exploiting CVE-2023-36025 using URL shortcut exploits, with evidence of LiteLLM installation; however, it provides no specific exploit code, patches, or detailed technical information.

    001921.9K
    13.4K followersView on X
  • ܛܔܔܔܛܔܛܔܛ@skocherhan
    General

    cve-2023-36025 cve-2023-32046 https://t.co/1SbjyiAodo

    Post summary

    The tweet merely lists two CVE identifiers and a URL, with no additional context or details provided.

    00000113
    26.9K followersView on X
CPE platform detail26 entries

26 of 26 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1507--x64
OSmicrosoftwindows_10_1507--x86
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809--arm64
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_21h2--arm64
OSmicrosoftwindows_10_21h2--x64
OSmicrosoftwindows_10_21h2--x86
OSmicrosoftwindows_10_22h2--arm64
OSmicrosoftwindows_10_22h2--x64
OSmicrosoftwindows_10_22h2--x86
OSmicrosoftwindows_11_21h2--arm64
OSmicrosoftwindows_11_21h2--x64
OSmicrosoftwindows_11_22h2--arm64
OSmicrosoftwindows_11_22h2--x64
OSmicrosoftwindows_11_23h2--arm64
OSmicrosoftwindows_11_23h2--x64
OSmicrosoftwindows_server_2008--x86
OSmicrosoftwindows_server_2008r2-x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---

Explore more