CVE-2023-36025
ENISA EUVD: EUVD-2023-40009 ↗
Exploited in the Wild
✓ Confirmed 0-Day
Triaged: March 5, 2026
13 articles
Published: 2023-11-14
EPSS Score
Source: FIRST.org · 2026-05-23
91.47%
probability
This CVE has a 91.47% probability
of being exploited in the next 30 days.
0%
Top 99.7th percentile of all CVEs
100%
CVSS v3.1
Source: VulnerabilityLookup (CIRCL)8.8
HIGH
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Temporal
Exploit Code Maturity
Functional
Remediation Level
Official Fix
Report Confidence
Confirmed
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
Description
NVDWindows SmartScreen Security Feature Bypass Vulnerability
Affected Products
Microsoft
Windows 10 Version 1809
10.0.17763.0
Microsoft
Windows 10 Version 1809
10.0.0
Microsoft
Windows Server 2019
10.0.17763.0
Microsoft
Windows Server 2019 (Server Core installation)
10.0.17763.0
Microsoft
Windows Server 2022
10.0.20348.0
Exploits & PoC
ka7ana/CVE-2023-36025
Quick test for CVE-2023-26025 behaviours
13
2023-11-29
J466Y/test_CVE-2023-36025
test repo for CVE-2023-36025
5
2023-11-28
coolman6942o/-EXPLOIT-CVE-2023-36025
Windows SmartScreen Security Feature Bypass Vulnerability
5
2023-12-29
3 repos — triés par ⭐
Rechercher sur GitHub ↗
Signal Intelligence
Confidence
85%
EPSS
91.47%
CVSS v3.1
8.8
Mentions
13
Last Seen
Aug 13, 2024
CNA Information
CNA Assigner
microsoft
CNA Title
Windows SmartScreen Security Feature Bypass Vulnerability
Analyst Note
CVE-2023-36025 is explicitly named as a zero-day exploited in the wild since March 2023, preceding the November 2023 patch publication. Multiple authoritative sources (BleepingComputer, CERT-EU) confirm active exploitation in malware attacks before patch availability, meeting all zero-day criteria.
Threat Actors 9
APT 29
apt_group
Information theft and espionage
🇷🇺 RU
Vicious Panda
apt_group
Information theft and espionage
🇨🇳 CN
Evilnum
apt_group
Information theft and espionage
Opal Sleet
apt_group
🇰🇵 KP
Void Banshee
apt_group
unknown
TA571
apt_group
🇷🇺 RU
The White Company
apt_group
Information theft and espionage
🇨🇳 CN
Mana Team
apt_group
🇨🇳 CN
APT 5
apt_group
Information theft and espionage
🇨🇳 CN
Triage Info
Decided atMar 05, 2026
Published DateNov 14, 2023