Junglewise Threat Intelligence

CVE-2022-41049: Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability

CVE-2022-41049 · Severity: critical · CVSS 5.4 · Exploited in the wild · Published 2022-11-14

Technologies: Microsoft Windows Server 2022, Microsoft Windows Server 2019, Microsoft Windows 11, Microsoft Windows, Microsoft Windows Server 2012, Microsoft Windows 10, Microsoft Windows 8.1, Microsoft Windows Server 2016, Microsoft Windows Server 2008. Vendors: Microsoft.

Executive brief

Microsoft Windows contains a security feature bypass vulnerability in the Mark of the Web (MOTW) mechanism. An attacker can exploit this to prevent security features from correctly identifying and restricting files downloaded from the internet, leading to a limited loss of integrity and availability.

Affected products

  • Microsoft Windows 10 versions up to (excluding) 10.0.10240.19567, 10.0.14393.5501, 10.0.17763.3650, 10.0.19042.2251, 10.0.19043.2251, 10.0.19044.2251, 10.0.19045.2251
  • Microsoft Windows 11 versions up to (excluding) 10.0.22000.1219, 10.0.22621.819
  • Microsoft Windows Server 2016 versions up to (excluding) 10.0.14393.5501
  • Microsoft Windows Server 2019 versions up to (excluding) 10.0.17763.3650
  • Microsoft Windows Server 2022 versions up to (excluding) 10.0.20348.1249
  • Microsoft Windows 7 SP1
  • Microsoft Windows 8.1
  • Microsoft Windows Server 2008
  • Microsoft Windows Server 2012

Timeline

  • 2022-11-14: disclosed
  • 2022-11-14: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-11-14: patched: Microsoft released security updates to address this vulnerability.
  • 2022-11-14: exploited: Reported as exploited in the wild.

Related threats