CVE-2022-41049
KEVmassMark of the Web Security Feature Bypass in Microsoft Windows
CISA: Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability
CVE-2022-41049 is a security feature bypass in Microsoft Windows' Mark of the Web (MOTW), the mechanism that flags files downloaded from the internet so that SmartScreen and other user-facing warnings fire before such files are opened. Because it is a bypass rather than a direct code-execution bug, it is triggered when a crafted or locally delivered file arrives without (or loses) the MOTW tag, typically via email, a download, or a payload dropped by another exploit, so the file opens with no 'downloaded from the internet' warning. An attacker who chains this bypass with another flaw gains a materially better chance of executing malware without alerting the user, which is reflected in the CVSS score (network vector, user interaction required, partial integrity and availability impact, no confidentiality impact). Virtually every supported Windows 10 and Windows 11 client and every Windows Server 2016, 2019, and 2022 deployment is affected. The flaw was among six actively exploited zero-days patched in Microsoft's November 2022 updates and was added to CISA's Known Exploited Vulnerabilities catalog on November 14, 2022; CISA lists ransomware use as unknown and no public proof-of-concept is known.
What to do: Apply Microsoft's November 2022 cumulative Windows security update to all Windows 10, Windows 11, and Windows Server 2016/2019/2022 systems, prioritizing user-facing endpoints since exploitation requires user interaction. Because the flaw is on CISA's KEV catalog, patching is a required action per vendor instructions and should be treated as urgent; keep SmartScreen and MOTW-based protections enabled and verify that endpoint or proxy tooling is not stripping MOTW tags from downloaded files.
| microsoft Windows 10 | 1507, 1607, 1809, 20H2, 21H1, 21H2, 22H2 (all builds prior to the November 2022 security updates) |
| microsoft Windows 11 | 21H2, 22H2 (all builds prior to the November 2022 security updates) |
| microsoft Windows Server 2016 | all editions (prior to the November 2022 security updates) |
| microsoft Windows Server 2019 | all editions (prior to the November 2022 security updates) |
| microsoft Windows Server 2022 | all editions (prior to the November 2022 security updates) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Windows Mark of the Web Security Feature Bypass Vulnerability
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1809, windows 10 20h2, windows 10 21h1, windows 10 21h2, windows 10 22h2, windows 11 21h2, windows 11 22h2, windows server 2016, windows server 2019, windows server 2022
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L