Skip to main content
Mallory
HighCISA KEVExploited in the wildPublic exploit

Windows SmartScreen Internet Shortcut (.url) Security Feature Bypass

IdentifiersCVE-2023-36025CWE-693

CVE-2023-36025 is a Windows SmartScreen security feature bypass vulnerability affecting the handling of Internet Shortcut (.url) files. According to the provided content, the flaw stems from missing or improper checks and corresponding warning prompts for specially crafted .url files, allowing attacker-supplied shortcuts or hyperlinks to such shortcuts to evade Windows Defender SmartScreen protections. In observed exploitation chains, a user is enticed to click a malicious .url file or a hyperlink pointing to one; the shortcut then retrieves or launches follow-on content such as VBScript from remote infrastructure, leading to execution of additional payloads. The vulnerability has been exploited in the wild and has been used in campaigns delivering malware including DarkGate, Phemedrone Stealer, and Mispadu.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation bypasses Windows Defender SmartScreen checks and associated security prompts that would normally warn users before opening untrusted Internet-origin content. This materially reduces user-visible friction and enables downstream malware delivery and execution. In the campaigns referenced in the content, exploitation facilitated execution chains involving VBScript and PowerShell, resulting in deployment of malware such as DarkGate RAT, Phemedrone Stealer, and other payloads used for credential theft, data theft, persistence, and remote access.

Mitigation

If you can’t patch tonight, do this now.

Until patching is complete, reduce exposure by blocking or tightly controlling delivery and execution of .url files from untrusted sources, including email attachments, web downloads, WebDAV shares, and hyperlinks to remote shortcut files. Harden controls around script execution, especially WScript/CScript, PowerShell, and remote content retrieval from UNC/WebDAV paths. Use attachment filtering, web proxy controls, ASR policies, and endpoint detections for suspicious .url, .vbs, and PowerShell execution chains. User awareness measures may help, but they are not sufficient because the vulnerability specifically weakens SmartScreen warning behavior.

Remediation

Patch, then assume compromise.

Apply Microsoft's security update for CVE-2023-36025 released in November 2023. Because the vulnerability is actively exploited in the wild and has been added to CISA's Known Exploited Vulnerabilities catalog, affected systems should be updated on an urgent basis. Ensure Windows systems are fully patched with the relevant cumulative/security updates that correct SmartScreen handling of Internet Shortcut (.url) files.
PUBLIC EXPLOITS

Exploits

2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.

VALID 2 / 2 TOTALView more in app
-EXPLOIT-CVE-2023-36025MaturityPoCVerified exploit

This repository provides an exploit for CVE-2023-36025, a Windows SmartScreen Security Feature Bypass vulnerability. The main exploit is implemented in 'CVE-2023-36025.vbs', a VBScript file that launches a Python-based reverse shell. The script, when executed on a vulnerable Windows system, connects back to a specified attacker's IP address and TCP port (default: 172.27.136.131:8888), providing the attacker with a remote shell. The repository also includes a .url shortcut file pointing to the VBScript, and a README with usage instructions. The exploit requires the attacker to set up a reverse TCP handler (such as Metasploit's multi/handler) to receive the shell. The payload is operational and provides remote command execution on the target system. The repository is small, with three files: the exploit script, a shortcut, and documentation.

coolman6942oDisclosed Dec 28, 2023vbscriptpythonnetwork
CVE-2023-36025MaturityPoCVerified exploit

This repository is a proof-of-concept (PoC) for CVE-2023-36025, a vulnerability affecting Microsoft Windows. The repository contains a README describing the exploit and a .url file (testing.url) that references a script inside a ZIP archive via a file:// URL. The exploit demonstrates how a specially crafted .url file can be used to trigger the vulnerability when the referenced ZIP file is hosted on a server accessible to the victim. There is no executable code; the exploit relies on the victim opening the .url file, which then attempts to access and potentially execute a script from within the ZIP file. The repository is minimal and intended for demonstration and testing purposes only.

ka7anaDisclosed Nov 17, 2023local
EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
Microsoft CorporationWindows 10 1507operating_system
Microsoft CorporationWindows 10 1607operating_system
Microsoft CorporationWindows 10 1809operating_system
Microsoft CorporationWindows 10 21h2operating_system
Microsoft CorporationWindows 10 22h2operating_system
Microsoft CorporationWindows 11 21h2operating_system
Microsoft CorporationWindows 11 22h2operating_system
Microsoft CorporationWindows 11 23h2operating_system
Microsoft CorporationWindows Server 2008operating_system
Microsoft CorporationWindows Server 2008 R2operating_system
Microsoft CorporationWindows Server 2008 Sp2operating_system
Microsoft CorporationWindows Server 2012operating_system
Microsoft CorporationWindows Server 2012 R2operating_system
Microsoft CorporationWindows Server 2016operating_system
Microsoft CorporationWindows Server 2019operating_system
Microsoft CorporationWindows Server 2022operating_system
Microsoft CorporationWindows Server 23h2operating_system

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware3

Malware families riding this exploit, with evidence and IOCs.

Detection signatures1

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity2

Community discussion across Reddit, Mastodon, and other social sources.