MEDIUM
CVE-2022-41049
CVSS
5.4
KEV
Description
Windows Mark of the Web Security Feature Bypass Vulnerability
Summary dbcve.org
This is a security feature bypass in Windows Mark of the Web (MOTW), a Windows security feature that adds a zone identifier to files downloaded from the internet to warn users before opening potentially malicious content. The vulnerability allows attackers to circumvent this protection mechanism, enabling malicious files to be opened without security warnings.
Mitigation
Apply the Microsoft security updates for this vulnerability (CVE-2022-41049) to affected Windows systems.
EPSS Score
2.49%
Probability of exploitation in next 30 days
84th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.