MEDIUM

CVE-2022-41049

Microsoft Windows 10 1507 2022-11-09 CVSS v3.1
CVSS
5.4
KEV

Description

Windows Mark of the Web Security Feature Bypass Vulnerability

Summary dbcve.org

This is a security feature bypass in Windows Mark of the Web (MOTW), a Windows security feature that adds a zone identifier to files downloaded from the internet to warn users before opening potentially malicious content. The vulnerability allows attackers to circumvent this protection mechanism, enabling malicious files to be opened without security warnings.

Mitigation

Apply the Microsoft security updates for this vulnerability (CVE-2022-41049) to affected Windows systems.

Patch Commit

EPSS Score

2.49%
Probability of exploitation in next 30 days
84th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE