November 14, 2023 · Applied Cybernetics Group
CVE-2023-36025 — Microsoft Windows
Microsoft Windows SmartScreen Security Feature Bypass Vulnerability
- Added to KEV
2023-11-14- Federal due date
2023-12-05- Vendor
- Microsoft
- Product
- Windows
- EPSS
- 99.6th percentile (score 0.902, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2023-36025
CISA short description
Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to bypass Windows Defender SmartScreen checks and their associated prompts.
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.