HIGH

CVE-2022-41128

Microsoft Windows 10 1507 2022-11-09 CVSS v3.1
CVSS
8.8
KEV

Description

Windows Scripting Languages Remote Code Execution Vulnerability

Summary dbcve.org

CVE-2022-41128 is a remote code execution vulnerability in Windows scripting languages (JScript and VBScript scripting engines). The vulnerability allows attackers to execute arbitrary code on affected Windows systems through specially crafted script content.

Mitigation

Apply the relevant Microsoft security updates for affected Windows versions. Until patches are applied, restrict execution of untrusted JScript/VBScript files and disable scripting engines via group policy where feasible.

Patch Commit

Weakness (CWE)

CWE-787 Out-of-bounds Write

EPSS Score

24.62%
Probability of exploitation in next 30 days
97.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE