Vulnerability record · CVE-2023-32049 · published 11 July 2023
CVE-2023-32049: Windows SmartScreen security feature bypass
Microsoft · Windows 10 1607
CVE-2023-32049 is a security feature bypass in Microsoft Windows SmartScreen, the component that warns users about untrusted files and downloads. A successful bypass undermines that warning, letting a malicious file run without the expected SmartScreen prompt. It affects a broad set of Windows 10, Windows 11 and Windows Server releases.
Description
Windows SmartScreen Security Feature Bypass Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is in CISA KEV with confirmed in-the-wild exploitation and a high CVSS score, but requires user interaction and the record lacks technical detail on the bypass mechanism.
What it is
CVE-2023-32049 is a security feature bypass in Microsoft Windows SmartScreen, the component that warns users about untrusted files and downloads. A successful bypass undermines that warning, letting a malicious file run without the expected SmartScreen prompt. It affects a broad set of Windows 10, Windows 11 and Windows Server releases.
Impact
An attacker can evade SmartScreen reputation and warning checks so a user opens or runs a malicious file that would normally be flagged. The CVSS vector rates high confidentiality, integrity and availability impact, though the record gives no further detail on the exact mechanism.
Attack surface
Reached over the network (AV:N) with no privileges required (PR:N), but user interaction is required (UI:R), meaning the victim must open or execute the crafted content. No authentication is needed on the attacker side.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2023-07-11 with a remediation due date of 2023-08-01, indicating exploitation in the wild. EPSS 30-day probability is about 4.2 percent (90th percentile); no ransomware campaign use is recorded.
What to do
- Apply the Microsoft updates referenced in the MSRC advisory for all affected Windows 10, Windows 11 and Windows Server versions.
- Prioritize patching internet-facing and user-facing endpoints, since exploitation requires a user to open crafted content.
- Where patching is delayed, restrict execution of untrusted downloads and enforce application allowlisting.
- Keep SmartScreen and Defender protections enabled and current, and treat SmartScreen bypasses as a reason to scrutinize email and web-delivered files.
Detection
- Monitor for processes executing files from download or temp directories that bypass normal SmartScreen prompts.
- Alert on SmartScreen or Defender events indicating a warning was suppressed or a reputation check failed.
- Hunt for email or web-delivered files that execute shortly after download with no user-facing security prompt.
- Correlate endpoint execution telemetry with known CVE-2023-32049 exploitation indicators from vendor and CISA guidance.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-32049 to the Known Exploited Vulnerabilities catalog on 11 July 2023 as "Microsoft Windows Defender SmartScreen Security Feature Bypass Vulnerability". Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable. Federal deadline 1 August 2023.
Affected products
9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-32049 | PatchVendor Advisory |
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-32049 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-32049 | US Government Resource |
Track CVE-2023-32049 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-32049), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.