RaqibCTI
CVE

CVE-2024-38217

P2
Microsoft Windows Mark of the Web (MOTW) Protection Mechanism Failure Vulnerability
Microsoft · Windows
Date added (CISA)
2024-09-10
Remediation due
2024-10-01
Known ransomware use
Not indicated
Remediation priority
P2past CISA due date

Description

Microsoft Windows Mark of the Web (MOTW) contains a protection mechanism failure vulnerability that allows an attacker to bypass MOTW-based defenses. This can result in a limited loss of integrity and availability of security features such as Protected View in Microsoft Office, which rely on MOTW tagging.

Source: NVD ↗ · CISA KEV Catalog ↗