CVE-2024-29988 is a critical SmartScreen Prompt Security Feature Bypass Vulnerability affecting multiple versions of Microsoft Windows and Windows Server. With a CVSS score of 8.8 (HIGH), it allows an unauthenticated attacker to achieve high confidentiality, integrity, and availability impact with low attack complexity, requiring user interaction. This vulnerability is actively exploited in the wild, as confirmed by its presence in the KEV catalog and numerous media reports detailing its use in malware attacks. Despite active exploitation, no public exploit code is currently available in Metasploit, Nuclei, or ExploitDB, though it has garnered significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.17763.5696CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:arm64:* | ||
< 10.0.17763.5696CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:* | ||
< 10.0.17763.5696CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:* | ||
< 10.0.19044.4291CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:* | ||
< 10.0.19045.4291CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.