ZeroHour

CVE-2022-41128

KEVmass

Out-of-bounds Write RCE in Microsoft Windows JScript9 Scripting Engine

CISA: Microsoft Windows Scripting Languages Remote Code Execution Vulnerability

CVSS 3.1
8.8 high
EPSS
25%p98
Published
()
KEV added
AI analysis

CVE-2022-41128 is a remote code execution flaw in the JScript9 scripting language on Microsoft Windows, classed by the CWE taxonomy as an out-of-bounds write (CWE-787), meaning crafted input can write past the end of an allocated memory buffer. Microsoft's description is limited, but flaws of this type in scripting engines are typically triggered when the engine processes attacker-crafted script content, such as script embedded in a web page or document. Successful exploitation would let an attacker execute arbitrary code in the context of the affected process on the target Windows system. Any Windows deployment that processes content through the JScript9 engine is affected, which spans a broad share of the Windows installed base. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-11-08, indicating confirmed in-the-wild exploitation; no public proof-of-concept is known, EPSS puts the 30-day exploitation probability at 24.6% (98th percentile), and ransomware use is unknown.

What to do: Apply Microsoft's Windows security updates per vendor instructions without delay, prioritizing internet-facing and user-workstation systems because the flaw is KEV-listed as actively exploited. Until patched, limit exposure to untrusted script-bearing web content and documents from unverified sources, and verify remediation status against Microsoft's update guidance.

Affected
Microsoft Windows
Estimated exposure
mass≈1 billion+ Windows devices (order of magnitude; the engine ships with Windows itself) — Windows runs on roughly a billion-plus devices worldwide, and the JScript9 scripting engine is a Windows component, so the potential exposed population is effectively the Windows installed base rather than a countable product population.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows Scripting Languages Remote Code Execution Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 20h2, windows 10 21h1, windows 10 21h2, windows 10 22h2, windows 11 21h2, windows 11 22h2, windows 7, windows 8.1, windows server 2008
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news