CVE-2024-38217
Microsoft Windows Mark of the Web (MOTW) Protection Mechanism Failure Vulnerability
CVSS
5.4
Medium
EPSS
10.0%
p95
KEV
YES
Sep 10, 2024
Exploit Today
79
0-100
Published: Sep 10, 2024 · Last modified: Aug 10, 2026 · CWE-693
Product
Microsoft / Windows
Vulnerability
Microsoft Windows Mark of the Web (MOTW) Protection Mechanism Failure Vulnerability
Added to KEV
Sep 10, 2024
Remediate by
Oct 1, 2024
Known ransomware use
No
Summary description
Microsoft Windows Mark of the Web (MOTW) contains a protection mechanism failure vulnerability that allows an attacker to bypass MOTW-based defenses. This can result in a limited loss of integrity and availability of security features such as Protected View in Microsoft Office, which rely on MOTW tagging.
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38217; https://nvd.nist.gov/vuln/detail/CVE-2024-38217
Windows Mark of the Web Security Feature Bypass Vulnerability