MEDIUM

CVE-2022-41091

Microsoft Windows 10 1507 2022-11-09 CVSS v3.1
CVSS
5.4
KEV

Description

Windows Mark of the Web Security Feature Bypass Vulnerability

Summary dbcve.org

This is a security feature bypass vulnerability in Windows Mark of the Web (MOTW), which is a Windows security mechanism that tags files downloaded from the internet or originating from untrusted sources with metadata to apply restrictive behaviors. The vulnerability allows attackers to circumvent these protections, potentially enabling malicious files to execute with fewer restrictions than intended.

Mitigation

Apply the Microsoft security update for CVE-2022-41091 to affected Windows systems; ensure Windows Update is enabled and systems are patched to the latest supported releases.

Patch Commit

Weakness (CWE)

CWE-863 Incorrect Authorization

EPSS Score

1.81%
Probability of exploitation in next 30 days
77.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE