ZeroHour

CVE-2022-41049

KEVmass

Mark of the Web Security Feature Bypass in Microsoft Windows

CISA: Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability

CVSS 3.1
5.4 medium
EPSS
2%p84
Published
()
KEV added
AI analysis

CVE-2022-41049 is a security feature bypass in Microsoft Windows' Mark of the Web (MOTW), the mechanism that flags files downloaded from the internet so that SmartScreen and other user-facing warnings fire before such files are opened. Because it is a bypass rather than a direct code-execution bug, it is triggered when a crafted or locally delivered file arrives without (or loses) the MOTW tag, typically via email, a download, or a payload dropped by another exploit, so the file opens with no 'downloaded from the internet' warning. An attacker who chains this bypass with another flaw gains a materially better chance of executing malware without alerting the user, which is reflected in the CVSS score (network vector, user interaction required, partial integrity and availability impact, no confidentiality impact). Virtually every supported Windows 10 and Windows 11 client and every Windows Server 2016, 2019, and 2022 deployment is affected. The flaw was among six actively exploited zero-days patched in Microsoft's November 2022 updates and was added to CISA's Known Exploited Vulnerabilities catalog on November 14, 2022; CISA lists ransomware use as unknown and no public proof-of-concept is known.

What to do: Apply Microsoft's November 2022 cumulative Windows security update to all Windows 10, Windows 11, and Windows Server 2016/2019/2022 systems, prioritizing user-facing endpoints since exploitation requires user interaction. Because the flaw is on CISA's KEV catalog, patching is a required action per vendor instructions and should be treated as urgent; keep SmartScreen and MOTW-based protections enabled and verify that endpoint or proxy tooling is not stripping MOTW tags from downloaded files.

Affected
microsoft Windows 101507, 1607, 1809, 20H2, 21H1, 21H2, 22H2 (all builds prior to the November 2022 security updates)
microsoft Windows 1121H2, 22H2 (all builds prior to the November 2022 security updates)
microsoft Windows Server 2016all editions (prior to the November 2022 security updates)
microsoft Windows Server 2019all editions (prior to the November 2022 security updates)
microsoft Windows Server 2022all editions (prior to the November 2022 security updates)
Estimated exposure
mass≈1 billion+ devices (affected versions span the entire supported Windows 10/11 client and Windows Server 2016–2022 installed base) — Windows runs on well over a billion devices worldwide, and the affected CPE entries cover every supported Windows 10/11 release and Windows Server 2016–2022 at the time of disclosure, so essentially the whole Windows installed base was…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows Mark of the Web Security Feature Bypass Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 20h2, windows 10 21h1, windows 10 21h2, windows 10 22h2, windows 11 21h2, windows 11 22h2, windows server 2016, windows server 2019, windows server 2022
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L

In the news