Microsoft has patched a flaw in Windows Smart App Control and SmartScreenthat has been used as a zero-day in attackssince at least 2018.
See also: North Korean hackers distribute FudModule rootkit via Chrome zero-day

On vulnerable systems, threat actors abused the zero-day (CVE-2024-38217) to bypass the Smart App Control and Mark of the Web (MotW)to launch untrusted or potentially dangerous binaries and applications without warnings.
" To exploit this vulnerability, an attacker could host a file on a server controlled by the attacker and then convince a targeted user to download and open the file. This could allow the attacker to interfere with the functionality of Mark of the Web ," Microsoft explained in a security advisory it recently published
Smart App Control in Windows 11 uses Microsoft 's app intelligence services and code integrity features to detect and block potentially harmful apps or binaries.
See also: Hackers exploit zero-day vulnerability to target internet service providers in the US
Smart App Control replaces SmartScreen in Windows 11. However, SmartScreen will automatically take over if Smart App Control is not enabled to protect against malicious content. Both security features are triggered when users try to open files that are labeled “Mark of the Web.”

Last month, Elastic Security Labs disclosed CVE-2024-38217 as a flaw in LNK file handling, known as LNK stomping. This zero-day allows attackers to bypass Smart App Control security features that otherwise prevent untrusted applications from launching.
LNK stomping involves creating LNK files with unconventional target paths or internal structures. When a user clicks on one of these files, Windows Explorer (explorer.exe) automatically adapts the LNK file to use its normal formatting. However, this process also removes the “Mark of the Web” (MotW) tag from the downloaded files, a marker that Windows security features use to trigger an automated security check.
See also: Google Chrome: The tenth zero-day bug of this year has been fixed
A zero-day vulnerability, such as the one in Smart App Control, refers to a software security flaw that is unknown to the vendor and remains unpatched ,allowing attackers to exploit it before the developer has a chance to issue a fix. The term “zero-day” implies that there are zero days of protection against such vulnerabilities, as attackers discover and exploit them in real time. These flaws can be incredibly dangerous, often leading to major breaches , data theft, or the installation of malware. Organizations must remain vigilant and implement strong security measures to protect their systems from potential zero-day exploits.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
