CVE-2022-41091
KEV ransomwaremassWindows Mark of the Web (MOTW) Security Feature Bypass, Actively Exploited
CISA: Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability
CVE-2022-41091 is a security feature bypass (CWE-863, incorrect authorization) in Microsoft Windows' Mark of the Web (MOTW) mechanism, which tags files downloaded from the internet so Windows can apply protective warnings such as SmartScreen prompts before the content runs. An attacker delivers a crafted file — typically a script or JavaScript payload — that fails to receive or retain the MOTW designation, so Windows treats it as locally created and the usual user warnings are skipped; exploitation requires user interaction (opening or running the file), per the CVSS vector. The bypass lets malware execute with fewer prompts, and Google's Threat Analysis Group reported that the Magniber ransomware gang used this flaw as a zero-day to launch JavaScript-delivered ransomware without MOTW-based warnings. Anyone running the affected Windows 10 builds (1507 through 22H2), Windows 11 (21H2 and 22H2), or Windows Server 2016/2019/2022 is affected. The flaw was actively exploited and added to CISA's Known Exploited Vulnerabilities catalog on 2022-11-08 with known ransomware use; Microsoft patched it in the November 2022 Patch Tuesday release (68 vulnerabilities, six zero-days), and no public PoC is known.
What to do: Apply the November 2022 Windows security updates (released 2022-11-08) to all affected Windows 10, Windows 11, and Windows Server systems; this flaw is in CISA KEV with known ransomware use, so treat patching as urgent. Because Magniber exploited the bypass via JavaScript-delivered payloads that lacked the MOTW flag, review endpoints for JavaScript droppers or ransomware indicators and scrutinize downloaded script files. Until patched, treat internet-downloaded files and scripts with extra suspicion since they may run without the usual warnings.
| Microsoft Windows 10 | 1507, 1607, 1809, 20H2, 21H1, 21H2, 22H2 |
| Microsoft Windows 11 | 21H2, 22H2 |
| Microsoft Windows Server 2016 | supported builds (see Microsoft advisory) |
| Microsoft Windows Server 2019 | supported builds (see Microsoft advisory) |
| Microsoft Windows Server 2022 | supported builds (see Microsoft advisory) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Windows Mark of the Web Security Feature Bypass Vulnerability
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1809, windows 10 20h2, windows 10 21h1, windows 10 21h2, windows 10 22h2, windows 11 21h2, windows 11 22h2, windows server 2016, windows server 2019, windows server 2022
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L