Critical vulnerability bypassing Windows SmartScreen warning shows why layered security defences matter

A security researcher working at Fortinetโ€™s FortiGuard Labs has revealed how a high-rated vulnerability in Microsoftโ€™s Windows SmartScreen protection bypassed warning dialogues to deliver malware.

CVE-2024-21412 is known to have been exploited in the wild but was patched by Microsoft in February. The NIST National Vulnerability Database entry for CVE-2024-21412 states that the vulnerability has been โ€œmodified since it was last analysedโ€ and is currently โ€œawaiting reanalysis which may result in further changes to the information providedโ€.

What we know, however, is that the vulnerability is based on an error in the way that maliciously crafted files are handled and could lead to exploitation by information-stealing malware such as ACR Stealer and Lumia Stealer.

FortiGuard Labs researcher Cara Lin states in the newly published analysis that โ€œinitially, attackers lure victims into clicking a crafted link to a URL file designed to download an LNK file. The LNK file then downloads an executable file containing an HTA script. Once executed, the script decodes and decrypts PowerShell code to retrieve the final URLs, decoy PDF files, and a malicious shell code injector.โ€

Different injectors and PDFs are used so as to evade detection, and regions targeted so far include North America, Spain and Thailand.

The ACR Stealer malware is particularly nasty and can target applications as diverse as Google Chrome, Microsoft Edge, Mozilla Firefox, crypto wallets, Telegram, Signal, WhatsApp, BitWarden, 1Password, AnyDesk and MySQL Workbench to name but a few.

Experts: SmartScreen bypass emphasises importance of layered security defences

Sarah Jones, Cyber Threat Intelligence Research Analyst at Critical Start, warns that โ€œthis vulnerability has been actively exploited by multiple threat groups, emphasising the need for users to exercise caution and maintain updated security softwareโ€.

Even though the vulnerability itself has now been patched, understanding the tactics, techniques and procedures (TTPs) of malicious actors is critical in identifying personal business risk according to Ken Dunham, Cyber Threat Director at Qualys Threat Research Unit.

โ€œItโ€™s essential to employ an intelligence-driven program, mapping TTPs to your defensive infrastructure and maturity to ensure not only user awareness but also preventive technology controls and visibility,โ€ he said. โ€œPay attention also to industry standard best practices of threat and vulnerability patch management to keep your organisation safe.โ€

Mr Ngoc Bui, Cybersecurity Expert at Menlo Security, concludes that CVE-2024-21412 reveals the persistent and evolving nature of cyber threats targeting Microsoft’s SmartScreen.

โ€œIt demonstrates that attackers are constantly refining their tactics to bypass traditional security measures and deliver malicious payloads to high-value targets,โ€ said Bui. โ€œThis highlights the need for proactive threat intelligence and layered defences to protect against these sophisticated attacks.โ€

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.