A proof-of-concept of a Windows Themes (ThemeBleed) vulnerability with the identifier CVE-2023-38146 has been publicly released. This vulnerability allows attackers to execute code remotely.
See also: Windows 11 KB5030219: Brings improvements and bug fixes

The vulnerability is also known as ThemeBleed and has received a high severity rating of 8.8. An exploit can occur if the user opens a malicious .THEME created by the attacker.
The exploit code was released by Gabe Kirkpatrick, one of the researchers who reported the vulnerability to Microsoft on May 15 and was awarded $5,000 for the find. Microsoft reported CVE-2023-38146 two days ago during its September 2023 Patch Tuesday update.
Kirkpatrick discovered the vulnerability by examining “strange Windows file formats,” including .THEME for files used to customize the appearance of the operating system. These files contain references to “.msstyles” files. Normally, they shouldn’t contain code, but only graphical resources that are loaded when the theme file is opened.
The researcher observed that, when using the version number “999”, there is a significant discrepancy in the routine for processing the .MSSTYLES, between the time of verifying the signature of a DLL (“_vrf.dll”) and the time of loading the library. This creates a race condition.
See also: Microsoft Paint Windows 11: New tool for removing image background

Using a specially crafted .MSSTYLES, an attacker can exploit a vulnerability to replace a verified DLL with a malicious one, thereby allowing them to execute arbitrary code on the target device.
Kirkpatrick created a PoC exploit that opens the computer when the user launches a theme file.
The researcher also points out that downloading a theme file from the web triggers the “mark-of-the-web” warning, which can alert the user to any threats . However, this can be avoided if the attacker wraps the theme in a .THEMEPACK file , which is essentially a CAB file.
When launching the CAB file, the content launches automatically without displaying a mark-of-the-web warning.
Microsoft addressed the issue by completely removing the “version 999” feature. However, Kirkpatrick says the situation is still under discussion. Additionally, Microsoft failed to address the lack of mark-of-the-web warnings for themepack files.
Windows users are advised to install Microsoft's September 2023 security update package as soon as possible. This package fixes two zero-day exploitable vulnerabilities and 57 other security issues in various applications and system components.
See also: Windows 11: They will not force Edge on European users
PoCs, or proofs of concept, are essentially tests that demonstrate that a theoretical security hole or vulnerability can actually be used for malicious purposes. In the case of the “ThemeBleed” vulnerability, Gabe Kirkpatrick created a PoC exploit that managed to cause the Windows device to run arbitrary code when the user launched a theme file. This confirms the threat that this vulnerability represents and the importance of implementing the appropriate remediation measures immediately.
