CISA KEV · catalog date Nov 16, 2023 · first observed Jul 19, 2026
Evidence dossier
CVE-2023-36584
Windows Mark of the Web Security Feature Bypass Vulnerability
Exploited in the wild (CISA KEV since Nov 16, 2023). microsoft reports CVSS 3.1 5.4. EPSS estimates 3.1% exploit likelihood as of Aug 27, 2026.
As of Aug 27, 2026
Normalized restatement
Windows Mark of the Web Security Feature Bypass Vulnerability
- State
- PUBLISHED
- Published
- Oct 10, 2023
- Updated
- Jan 12, 2026
- Evidence coverage
- 92%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAmicrosoftOriginal evidence ↗
Record text: Windows Mark of the Web Security Feature Bypass Vulnerability
Inspect raw assertion
- Field
container- Value
- Windows Mark of the Web Security Feature Bypass Vulnerability
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 3.06% probability · 86.61th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.030550000000; percentile 0.866120000000
FIRST EPSS · score date Aug 27, 2026 · 86.6th percentile · first observed Aug 27, 2026
microsoft · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
Windows Mark of the Web Security Feature Bypass Vulnerability
Inspect raw assertion
- Field
container- Value
- Windows Mark of the Web Security Feature Bypass Vulnerability
Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability
3.06% probability · 86.61th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.030550000000; percentile 0.866120000000
Applicability
Cited product scope
Grouped from 1 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
33 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.10240.0", "lessThan": "10.0.10240.20232", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.14393.0", "lessThan": "10.0.14393.6351", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.0", "lessThan": "10.0.17763.4974", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.17763.0", "lessThan": "10.0.17763.4974", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.19043.0", "lessThan": "10.0.19041.3570", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.19045.0", "lessThan": "10.0.19045.3570", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.0", "lessThan": "10.0.22000.2538", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.22621.0", "lessThan": "10.0.22621.2428", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.1.7601.0", "lessThan": "6.1.7601.26769", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.1.7601.0", "lessThan": "6.1.7601.26769", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.0.6003.0", "lessThan": "6.0.6003.22317", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.0.6003.0", "lessThan": "6.0.6003.22317", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.0.6003.0", "lessThan": "6.0.6003.22317", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.2.9200.0", "lessThan": "6.2.9200.24523", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.3.9600.0", "lessThan": "6.3.9600.21620", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.3.9600.0", "lessThan": "6.3.9600.21620", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.2.9200.0", "lessThan": "6.2.9200.24523", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.14393.0", "lessThan": "10.0.14393.6351", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.14393.0", "lessThan": "10.0.14393.6351", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.17763.0", "lessThan": "10.0.17763.4974", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.17763.0", "lessThan": "10.0.17763.4974", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.20348.0", "lessThan": "10.0.20348.2031", "versionType": "custom"}]product-9851bd571b8ab08bca589cd73710badfef557d036f0fb7707f694f1c9f597cb4Linked exactInspect raw assertions
cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x86:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 1
- Logic
- OR
- Version bounds
- through excluding 10.0.10240.20232
- Match ID
7b7a6bbd-847f-492d-8c7f-f262e03f9ca3
cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x64:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 10.0.10240.20232
- Match ID
b344bccf-1083-4e59-81cb-9431ae5fb79f
product-a3084138383423221f61594e86f5b295e5e254acd7ae5284f45e0877a084db43Linked exactInspect raw assertions
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 4
- Logic
- OR
- Version bounds
- through excluding 10.0.17763.4974
- Match ID
c38dbdd3-bc41-4791-9754-2826e3f0698d
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:arm64:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 2
- Logic
- OR
- Version bounds
- through excluding 10.0.17763.4974
- Match ID
c57ac4fd-7539-48d3-9aab-ba623468c5d8
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 3
- Logic
- OR
- Version bounds
- through excluding 10.0.17763.4974
- Match ID
15f303be-3b6e-4b91-99a8-3d0135040c0f
product-e0c6c3f5c5e95b5b83fbbf719a7de2471749e1ca250bebf19bc7898a937a00edLinked exactInspect raw assertions
cpe:2.3:o:microsoft:windows_10_21h1:*:*:*:*:*:*:x86:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 7
- Logic
- OR
- Version bounds
- through excluding 10.0.19041.3570
- Match ID
6e3db4a4-5176-474d-983d-3a4c093d771a
cpe:2.3:o:microsoft:windows_10_21h1:*:*:*:*:*:*:x64:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 6
- Logic
- OR
- Version bounds
- through excluding 10.0.19041.3570
- Match ID
2ebc5e25-7b8a-4a8f-9c0a-2df0a89a2492
cpe:2.3:o:microsoft:windows_10_21h1:*:*:*:*:*:*:arm64:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 5
- Logic
- OR
- Version bounds
- through excluding 10.0.19041.3570
- Match ID
c86c5206-dd71-4841-90a0-96411c35e925
Affected-product evidence
Accepted scope and product mapping
11 canonical links · 1 source-reported links
vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-02e254d111ce604757a15650ef469f4f8365d6247da82ce3ac2695c3cfc7dc5f
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
f040cb62-d743-4a28-9c6f-004030cc0d63vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-217b1ab3d25f361a639824f86753d418b35aa2a816ee370bb71b5d1dd883d87a
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
2c5b956d-ec1e-4a6f-8838-bb8c3cb657716ea2b638-acb7-46e6-8c37-8331644173c2a4af0731-cbc4-4541-b8a0-953fec8ab68evendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-25a2932c0bbcb648f7e391c8b9d34c734e5085444c03c1c206b9d4c4baa80b25
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
b0fc1060-f124-4829-b39f-94f48b963c2avendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-5a80416e92fed0cddbb3d4f3840218b448dee11159824ad25a0353da566963fe
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
2eb44fef-b77f-4ac3-8eda-327cb31d5b028442408b-a490-42f8-9857-ac5697b7ec45vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-7fe28b5b5b17e017d9554204df059dd619746ffb5c80da87bcbfb1c52720d2f4
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
6e6bf7a3-a7bb-4217-9165-bfa11afac287735444d5-f156-40fc-8975-204989418ab4vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-9851bd571b8ab08bca589cd73710badfef557d036f0fb7707f694f1c9f597cb4
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0074f05c-4980-4395-96b6-4fc4fb90ef15ca0aade2-3b93-477b-a42f-b9878b5dc933vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-a3084138383423221f61594e86f5b295e5e254acd7ae5284f45e0877a084db43
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
7d6d0e55-e97d-40e2-b8a7-a36b77be69abb6d5a164-49fd-400e-b89c-ead03f8c6d60bcbb139f-a6c7-48d4-b672-c03857b34f1avendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-a6295b9daad3ca57ce70751badba5b7fe99229c8a562cc7400e8cfef3daccaee
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
5cff3213-7aed-4f34-b1a0-f0ab2be7e9886d3da5c0-36fe-4321-9a5a-9a43a75b38c682fa976e-d8c7-479d-b336-d19727322b36vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-d196d31962e613955a91e33e795c22dcfa7bf25173abebaca616a6350cce9ce1
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
cb36a6cf-c99b-4d78-9f83-98206437d23evendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-e0c6c3f5c5e95b5b83fbbf719a7de2471749e1ca250bebf19bc7898a937a00ed
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
72a1a789-60af-4d03-a755-809f1c4f88df7c0afcd8-3814-4161-9caf-6fb35ff9ef2b7e1de8fb-b240-4422-bcef-4a619099d04evendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-f8c509b6ec25f2a4338a23556be321da5a7c3e8da9f1a4c52f7f15dd0e9a0d2a
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
b0c173bb-ab80-4939-b5c2-56a64550ed0cec77a948-aacc-4d0a-b019-5c5e0087f54eCanonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 22
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
01551120-0f83-4685-bd63-004c6069be4313f5586c-a7f8-4f2b-a688-2d39d8c129921e04ceb6-0f09-4475-b6cf-6d373c2ce2bc2046c2bd-1d56-479f-9dd8-2c76966e532d22247301-9cbb-4504-a3bd-e1b505efa5f4248abed0-cb1e-4ac9-a33f-583471d4583e2c0859ef-fffd-40bc-9b06-199b9a10a72a2e09c740-ba7e-41d5-8c61-46efce2f637434ed429b-d654-43a4-8ddc-e7f57d4bbffa380646d9-b61c-40fa-90c6-a7eea374673b38f6386f-3a4a-4815-9b75-5cc8e83ab1fc49dc6467-95c2-4a32-88ce-2ff34194a9f853f4791f-1b02-4532-b402-70215fea10d567d009f8-129b-42ce-93f6-942a69dbc78d6e0272cb-9219-4a43-9a4f-b302fd1ba65a915377d5-9744-4435-9259-dfa298e32395ac438560-4a3a-48c4-a81f-abc7d1e9c594baa089fc-749c-42b6-9546-6dee41aeeca9c360b68b-b49c-4e67-8dd8-1fecceb0471ece28d685-e662-49ca-b73c-9d3543f70ca3d8ffa0c7-d131-4052-911d-e5b41fe05f14e75e9958-d868-47b4-8107-2a9020c95c5aAssessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:LCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L/E:F/RL:O/RC:CDirect CVE/CNA normalized decisions
microsoft
CVSS 3.1 · Primary · Original assertion · rank 1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L/E:F/RL:O/RC:C- Validation
- Valid match
- Recomputed
- 5.4
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.