CVE-2024-21412 is a critical Internet Shortcut Files Security Feature Bypass Vulnerability affecting multiple versions of Microsoft Windows and Windows Server. This vulnerability allows an attacker to bypass security features, potentially leading to high-impact compromise of confidentiality and integrity. With a CVSS score of 8.1 (High), it is easily exploitable over a network with low attack complexity, requiring user interaction. This zero-day vulnerability has been actively exploited in the wild, including in known ransomware campaigns, and has garnered significant community discussion and media attention, despite a lack of public exploit code.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.17763.5458CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:*:* | ||
< 10.0.19044.4046CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:* | ||
< 10.0.19045.4046CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:* | ||
< 10.0.22000.2777CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_21h2:*:*:*:*:*:*:*:* | ||
< 10.0.22621.3155CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.