DKDKCISSPSearch
Vulnerabilities

CVE-2023-36025 (SmartScreen Bypass) Vulnerability: Analysis & Detection | Huntress

CVE-2023-36025 is a flaw in how Windows Defender SmartScreen processes specific internet shortcut files ( .URL ).

DKCISSP News DeskHuntress4 Oct 2026, 5:30 am
CVE-2023-36025 (SmartScreen Bypass) Vulnerability: Analysis & Detection | Huntress
Image courtesy of Huntress. Original report
DKCISSP REPORT

CVE-2023-36025 is a flaw in how Windows Defender SmartScreen processes specific internet shortcut files ( .URL ).

The vulnerability was publicly disclosed and patched by Microsoft on November 14, 2023 (Patch Tuesday).

Indicators that CVE-2023-36025 is being attempted or has been exploited include: Suspicious .URL Files: Internet shortcuts where the URL= parameter points to a file:// or UNC path rather than a standard http:// or https:// website.

One notable campaign involved the Phemedrone Stealer , which used this vulnerability to bypass security checks and steal sensitive data from cryptocurrency wallets, Discord, and Telegram immediately after the vulnerability was disclosed.

Normally, SmartScreen analyzes files downloaded from the web ("Mark of the Web") and warns the user if the file is potentially dangerous.

The vulnerability affects a wide range of Windows operating systems.

By exploiting this vulnerability, an attacker can create a specially crafted .URL file that bypasses these checks entirely.

It is rated High (CVSS 8.8) because it allows for the silent execution of malicious payloads without the user receiving the expected warning prompts.

Endpoint Scanning: Use vulnerability scanners (Nessus, Qualys, Microsoft Defender) to identify endpoints that have not installed the November 2023 Cumulative Update .

The primary defense is patching, but defense-in-depth remains critical: Patch Immediately: Make sure you’ve applied the Microsoft November 2023 Security Update to all Windows endpoints.

What happened

CVE-2023-36025 is a flaw in how Windows Defender SmartScreen processes specific internet shortcut files ( .URL ).

The vulnerability was publicly disclosed and patched by Microsoft on November 14, 2023 (Patch Tuesday).

What changed

Indicators that CVE-2023-36025 is being attempted or has been exploited include: Suspicious .URL Files: Internet shortcuts where the URL= parameter points to a file:// or UNC path rather than a standard http:// or https:// website.

One notable campaign involved the Phemedrone Stealer , which used this vulnerability to bypass security checks and steal sensitive data from cryptocurrency wallets, Discord, and Telegram immediately after the vulnerability was disclosed.

Who is affected

Normally, SmartScreen analyzes files downloaded from the web ("Mark of the Web") and warns the user if the file is potentially dangerous.

The vulnerability affects a wide range of Windows operating systems.

Why it matters

By exploiting this vulnerability, an attacker can create a specially crafted .URL file that bypasses these checks entirely.

It is rated High (CVSS 8.8) because it allows for the silent execution of malicious payloads without the user receiving the expected warning prompts.

Technical details

Endpoint Scanning: Use vulnerability scanners (Nessus, Qualys, Microsoft Defender) to identify endpoints that have not installed the November 2023 Cumulative Update .

The primary defense is patching, but defense-in-depth remains critical: Patch Immediately: Make sure you’ve applied the Microsoft November 2023 Security Update to all Windows endpoints.

At the time of release, Microsoft confirmed it was already being exploited in the wild as a zero-day.

Response

Successful exploitation leads to the deployment of ransomware, data theft (stealers), or full remote control of the victim's machine.

If you are running an unpatched version of any of the following, you are at risk: The core issue lies in how Windows parses Internet Shortcut ( .URL ) files that point to remote file shares.

What security teams should do

This restored the correct SmartScreen validation checks.

Behavioral Monitoring: Configure EDR to alert on .URL files being written to disk that contain UNC paths.

What remains unknown

Network Traffic: Outbound SMB (port 445) or WebDAV traffic initiated immediately after a user opens a file, especially to unknown external IP addresses.

Attribution

Huntress: CVE-2023-36025 is a flaw in how Windows Defender SmartScreen processes specific internet shortcut files ( .URL ).

What to watch next

Watch for new exploitation reports and updated indicators of compromise.

Watch for updated vendor guidance and fixed-version details.

MORE IN VULNERABILITIES

More cybersecurity reporting

Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCEThe Hacker News · 5 Oct 2026, 1:39 pmAttackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOTThe Hacker News · 5 Oct 2026, 1:00 pmCritical FortiMail zero-day exploited in the wild (CVE-2026-104286) - Help Net SecurityHelp Net Security · 2 Oct 2026, 2:20 pmTwo Zero-Days Exploited in Attack on Dutch Institute for VulnerabilityInfosecurity Magazine · 2 Oct 2026, 1:55 pm