September 10, 2024 · Applied Cybernetics Group
CVE-2024-38217 — Microsoft Windows
Microsoft Windows Mark of the Web (MOTW) Protection Mechanism Failure Vulnerability
- Added to KEV
2024-09-10- Federal due date
2024-10-01- Vendor
- Microsoft
- Product
- Windows
- EPSS
- 94.4th percentile (score 0.138, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2024-38217
CISA short description
Microsoft Windows Mark of the Web (MOTW) contains a protection mechanism failure vulnerability that allows an attacker to bypass MOTW-based defenses. This can result in a limited loss of integrity and availability of security features such as Protected View in Microsoft Office, which rely on MOTW tagging.
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.