Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
endpoint-software-vulnerabilitywidely-deployed-product-advisorydefense-evasion-methodinitial-access-method

Microsoft Patches Repeated Windows Mark-of-the-Web and SmartScreen Bypass Flaws

Updated 28d agoFirst seen May 25, 202625 sources

Microsoft has disclosed a sustained series of security feature bypass vulnerabilities across Windows and related components, with multiple advisories tied to Mark of the Web (MotW), SmartScreen, MapUrlToZone, Windows shortcut handling, and security zone mapping. The most detailed recent case, CVE-2026-32225, affects Windows Shell and allows attackers to bypass SmartScreen protections that rely on MotW by persuading a user to open a specially crafted .lnk file. Microsoft said successful exploitation could cause Windows to launch commands or Control Panel applets without proper MotW handling, potentially enabling arbitrary command execution or the loading of attacker-controlled DLLs; the flaw was rated Important, assigned a CVSS 8.8, marked as more likely to be exploited, and fixed at disclosure.

The newer Windows Shell issue follows a broader pattern of Microsoft fixes for related bypasses, including CVE-2022-44698 in Windows SmartScreen; CVE-2023-36564 in Windows Search; CVE-2023-36584, CVE-2024-38217, and CVE-2024-43487 in Windows Mark of the Web; CVE-2024-30073 in Windows Security Zone Mapping; CVE-2025-21328, CVE-2025-21329, and CVE-2025-21332 in MapUrlToZone; and CVE-2025-47160 in Windows Shortcut Files. Additional bypass advisories affected Microsoft products including Publisher, Office Developer Platform, PowerShell, Kerberos, Windows Hello, Surface, and PC Manager, underscoring Microsoft's continued effort to close gaps in trust labeling and execution safeguards that attackers can abuse to reduce warnings and increase the success of social-engineering attacks.

Share:
Microsoft Patches Repeated Windows Mark-of-the-Web and SmartScreen Bypass Flaws
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

16 events from the most recent confirmed update back to the earliest known activity.

16 EVENTS
Apr 14, 20262mo ago

Microsoft discloses PowerShell and Windows Shell bypass flaws

Microsoft published CVE-2026-26143 and CVE-2026-32225, covering Microsoft PowerShell and Windows Shell security feature bypass vulnerabilities. For CVE-2026-32225, Microsoft said exploitation was more likely, credited Jeong Lee, and released a fix at disclosure.

Oct 14, 20258mo ago

Microsoft discloses CVE-2025-53139 Windows Hello bypass

Microsoft published CVE-2025-53139, a Windows Hello security feature bypass vulnerability.

Sep 16, 20259mo ago

Microsoft discloses CVE-2025-49728 PC Manager bypass

Microsoft published CVE-2025-49728, a Microsoft PC Manager security feature bypass vulnerability.

Jul 8, 20251y ago

Microsoft discloses CVE-2025-49756 Office Developer Platform bypass

Microsoft published CVE-2025-49756, an Office Developer Platform security feature bypass vulnerability.

Jun 10, 20251y ago

Microsoft discloses CVE-2025-47160 shortcut files bypass

Microsoft published CVE-2025-47160, a Windows Shortcut Files security feature bypass vulnerability.

Mar 11, 20251y ago

Microsoft discloses CVE-2025-21247 MapUrlToZone bypass

Microsoft published CVE-2025-21247, a MapUrlToZone Security Feature Bypass Vulnerability, in its Security Update Guide. This adds a separate March 2025 bypass advisory not previously listed in the timeline.

CVE-2025-21247 - Security Update Guide - Microsoft - MapUrlToZone Security Feature Bypass Vulnerability

Microsoft discloses CVE-2025-26633 MMC bypass

Microsoft published CVE-2025-26633, a Microsoft Management Console security feature bypass vulnerability, in its Security Update Guide. The disclosure adds a new March 2025 bypass advisory not previously captured in the timeline.

CVE-2025-26633 - Security Update Guide - Microsoft - Microsoft Management Console Security Feature Bypass Vulnerability
Feb 11, 20251y ago

Microsoft discloses CVE-2025-21359 Windows Kernel bypass

Microsoft published CVE-2025-21359, a Windows Kernel security feature bypass vulnerability, in its Security Update Guide.

CVE-2025-21359 - Security Update Guide - Microsoft - Windows Kernel Security Feature Bypass Vulnerability

Microsoft discloses CVE-2025-21194 Surface bypass

Microsoft published CVE-2025-21194, a Microsoft Surface security feature bypass vulnerability, in its Security Update Guide.

Jan 14, 20251y ago

Microsoft discloses Kerberos and MapUrlToZone bypass flaws

Microsoft published CVE-2025-21299, CVE-2025-21328, CVE-2025-21329, and CVE-2025-21332, covering Windows Kerberos and multiple MapUrlToZone security feature bypass vulnerabilities.

Sep 10, 20242y ago

Microsoft discloses multiple Windows and Office bypass flaws

Microsoft published CVE-2024-30073, CVE-2024-38217, CVE-2024-38226, and CVE-2024-43487, covering Security Zone Mapping, Mark of the Web, Microsoft Publisher, and another Mark of the Web security feature bypass vulnerability. These advisories were released together on the same date.

Apr 9, 20242y ago

Microsoft discloses CVE-2024-29988 SmartScreen Prompt bypass

Microsoft published CVE-2024-29988, a SmartScreen Prompt Security Feature Bypass Vulnerability, in its Security Update Guide. This adds a separate April 2024 bypass advisory not previously captured in the timeline.

CVE-2024-29988 - Security Update Guide - Microsoft - SmartScreen Prompt Security Feature Bypass Vulnerability
Feb 13, 20242y ago

Microsoft discloses CVE-2024-21362 Windows Kernel bypass

Microsoft published CVE-2024-21362, a Windows Kernel security feature bypass vulnerability, in the Security Update Guide.

Oct 10, 20233y ago

Microsoft discloses CVE-2023-36584 Mark of the Web bypass

Microsoft published CVE-2023-36584, a Windows Mark of the Web security feature bypass vulnerability, on the same Patch Tuesday release cycle.

Microsoft discloses CVE-2023-36564 Windows Search bypass

Microsoft published CVE-2023-36564, a Windows Search security feature bypass vulnerability, in its Security Update Guide.

Dec 13, 20224y ago

Microsoft discloses CVE-2022-44698 SmartScreen bypass

Microsoft published guidance for CVE-2022-44698, a Windows SmartScreen security feature bypass vulnerability. This marks the earliest referenced disclosure in the set.

SOURCE COVERAGE

Sources

25 references tracked. Mallory keeps watching after this page renders.

25 SOURCESView all
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Microsoft Patches Repeated Windows Mark-of-the-Web and SmartScreen Bypass Flaws | Mallory