MEDIUM
CVE-2022-41091
CVSS
5.4
KEV
Description
Windows Mark of the Web Security Feature Bypass Vulnerability
Summary dbcve.org
This is a security feature bypass vulnerability in Windows Mark of the Web (MOTW), which is a Windows security mechanism that tags files downloaded from the internet or originating from untrusted sources with metadata to apply restrictive behaviors. The vulnerability allows attackers to circumvent these protections, potentially enabling malicious files to execute with fewer restrictions than intended.
Mitigation
Apply the Microsoft security update for CVE-2022-41091 to affected Windows systems; ensure Windows Update is enabled and systems are patched to the latest supported releases.
Weakness (CWE)
CWE-863
Incorrect Authorization
EPSS Score
1.81%
Probability of exploitation in next 30 days
77.6th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.