Skip to main content
Mallory
Back to intelligence
endpoint-software-vulnerabilitywidely-deployed-product-advisorypatch-regressiondefense-evasion-method

Microsoft Windows Updates: MOTW Bypass Patch and Windows 11 Shutdown Regression

Updated 2mo agoFirst seen Jan 20, 20262 sources

Microsoft issued security updates to remediate a Windows Remote Assistance protection-mechanism failure, CVE-2026-20824, that can allow attackers to bypass Mark of the Web (MOTW)—a key Windows control used to flag and apply additional restrictions to files originating from the internet. Reporting notes the issue is not “wormable” and requires local execution plus user interaction, but it can materially weaken common download-based defenses and be chained with other techniques to increase the likelihood of successful payload execution.

Separately, Microsoft released an out-of-band/emergency fix after a Patch Tuesday update introduced a Windows 11 23H2 regression where some systems configured with Secure Launch restart instead of shutting down (and may also fail to hibernate). A documented workaround for affected endpoints is to invoke shutdown via Command Prompt using:

shutdown /s /t 0

Other items in the set are not part of these Windows security/patch events: a PowerToys feature update, an iOS upgrade opinion piece, and a Windows 11 edition comparison.

Share:
Microsoft Windows Updates: MOTW Bypass Patch and Windows 11 Shutdown Regression
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Jan 19, 20264mo ago

Microsoft discloses Windows 11 shutdown bug affecting Secure Launch devices

Microsoft said some Windows 11 23H2 PCs configured with Secure Launch could no longer shut down normally after installing KB5073455, instead restarting when users selected Shut down. The company said it was investigating, advised users to save work to avoid data loss, and provided a Command Prompt shutdown workaround while noting no workaround for a related hibernation issue.

Jan 13, 20265mo ago

Microsoft patches Windows Remote Assistance MOTW bypass flaw

Microsoft released security updates to fix CVE-2026-20824, a Windows Remote Assistance vulnerability that could bypass Mark of the Web protections on downloaded files. The flaw could aid social-engineering attack chains by reducing security warnings and weakening controls that rely on MOTW metadata.

Microsoft releases KB5073455 Patch Tuesday update for Windows 11 23H2

Microsoft issued the Windows 11 23H2 update KB5073455 as part of Patch Tuesday. After installation, some systems later experienced a shutdown-related regression tied to Secure Launch configurations.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

11 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Microsoft Windows Updates: MOTW Bypass Patch and Windows 11 Shutdown Regression | Mallory