ZeroHour

CVE-2022-44698

KEV ransomwaremass1

SmartScreen Security Feature Bypass in Windows 10/11 and Windows Server

CISA: Microsoft Defender SmartScreen Security Feature Bypass Vulnerability

CVSS 3.1
5.4 medium
EPSS
76%p100
Published
()
KEV added
AI analysis

CVE-2022-44698 is a security feature bypass in Microsoft Defender SmartScreen in which specially crafted files do not properly trigger the SmartScreen Mark-of-the-Web warning prompt. The flaw is triggered over the network but requires user interaction: an attacker typically delivers a crafted file via a malicious link or phishing email, and when the user clicks or opens it, SmartScreen fails to show its usual warning. An attacker gains the ability to run malicious content on a user's machine without the standard SmartScreen prompt, making the flaw an effective delivery and initial-access aid — it has documented use in ransomware campaigns. Anyone running the affected Windows releases is exposed: Windows 10 versions 1607 through 22H2, Windows 11 21H2, and Windows Server 2016, 2019, and 2022. The vulnerability was exploited as a zero-day before patching, was added to CISA's Known Exploited Vulnerabilities catalog on 2022-12-13 with known ransomware use, and Google reported a ransomware gang abusing it in the wild.

What to do: Apply Microsoft's December 2022 security updates (or any later cumulative updates) for Windows 10, Windows 11, and Windows Server, prioritizing user workstations and systems exposed to phishing or web downloads, per the CISA KEV required action. Until patched, reinforce user awareness that downloaded files may not trigger the usual SmartScreen warning, and consider restricting download or execution of risky file types. Confirm remediation against CISA KEV guidance and treat this as high-priority given known ransomware exploitation.

Affected
microsoft Windows 101607, 1809, 20H2, 21H1, 21H2, 22H2
microsoft Windows 1121H2
microsoft Windows Server2016, 2019, 2022
Microsoft Defender (SmartScreen component)as shipped in the affected Windows releases
Estimated exposure
masshundreds of millions of Windows endpoints (SmartScreen is built into every affected Windows 10/11 and Windows Server installation) — SmartScreen ships by default in all affected Windows client and server releases, so exposure roughly tracks the installed base of Windows 10/11 and Windows Server, which public market-share data puts in the hundreds of millions of devices.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows SmartScreen Security Feature Bypass Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Defender
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 20h2, windows 10 21h1, windows 10 21h2, windows 10 22h2, windows 11 21h2, windows server 2016, windows server 2019, windows server 2022
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L

In the news