ZeroHour

CVE-2022-41091

KEV ransomwaremass

Windows Mark of the Web (MOTW) Security Feature Bypass, Actively Exploited

CISA: Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability

CVSS 3.1
5.4 medium
EPSS
2%p77
Published
()
KEV added
AI analysis

CVE-2022-41091 is a security feature bypass (CWE-863, incorrect authorization) in Microsoft Windows' Mark of the Web (MOTW) mechanism, which tags files downloaded from the internet so Windows can apply protective warnings such as SmartScreen prompts before the content runs. An attacker delivers a crafted file — typically a script or JavaScript payload — that fails to receive or retain the MOTW designation, so Windows treats it as locally created and the usual user warnings are skipped; exploitation requires user interaction (opening or running the file), per the CVSS vector. The bypass lets malware execute with fewer prompts, and Google's Threat Analysis Group reported that the Magniber ransomware gang used this flaw as a zero-day to launch JavaScript-delivered ransomware without MOTW-based warnings. Anyone running the affected Windows 10 builds (1507 through 22H2), Windows 11 (21H2 and 22H2), or Windows Server 2016/2019/2022 is affected. The flaw was actively exploited and added to CISA's Known Exploited Vulnerabilities catalog on 2022-11-08 with known ransomware use; Microsoft patched it in the November 2022 Patch Tuesday release (68 vulnerabilities, six zero-days), and no public PoC is known.

What to do: Apply the November 2022 Windows security updates (released 2022-11-08) to all affected Windows 10, Windows 11, and Windows Server systems; this flaw is in CISA KEV with known ransomware use, so treat patching as urgent. Because Magniber exploited the bypass via JavaScript-delivered payloads that lacked the MOTW flag, review endpoints for JavaScript droppers or ransomware indicators and scrutinize downloaded script files. Until patched, treat internet-downloaded files and scripts with extra suspicion since they may run without the usual warnings.

Affected
Microsoft Windows 101507, 1607, 1809, 20H2, 21H1, 21H2, 22H2
Microsoft Windows 1121H2, 22H2
Microsoft Windows Server 2016supported builds (see Microsoft advisory)
Microsoft Windows Server 2019supported builds (see Microsoft advisory)
Microsoft Windows Server 2022supported builds (see Microsoft advisory)
Estimated exposure
mass≈1B+ Windows client devices plus millions of Windows Server instances (Windows 10/11 dominate Microsoft's ~1.4B-device Windows install base) — MOTW is present on every affected Windows client and server build, so exposure scales with the global Windows 10/11 install base and widely deployed Windows Server fleets, less systems patched since the November 2022 release.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows Mark of the Web Security Feature Bypass Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 20h2, windows 10 21h1, windows 10 21h2, windows 10 22h2, windows 11 21h2, windows 11 22h2, windows server 2016, windows server 2019, windows server 2022
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L

In the news