Technical Severity
MEDIUM
CVSS v3.1 Metrics
5.4
/ 10
Minimal Risk
Critical
Vector Specification
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L/E:F/RL:O/RC:C
Exploitation Likelihood
EPSS Prediction
13.57
%
Predictive Probability
Percentile Rank
94.1
th
Documented as more likely to be exploited than 94.1% of known CVEs.
Detection Date
Sep 10, 2024
Remediation Due
Oct 01, 2024
CISA Catalog Active
Threat Analysis
Microsoft Windows Mark of the Web (MOTW) contains a protection mechanism failure vulnerability that allows an attacker to bypass MOTW-based defenses. This can result in a limited loss of integrity and availability of security features such as Protected View in Microsoft Office, which rely on MOTW tagging.
Remediation Directive
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.