CVE-2022-41049
Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability
CVSS
5.4
Medium
EPSS
2.4%
p83
KEV
YES
Nov 14, 2022
Exploit Today
75
0-100
Published: Nov 9, 2022 · Last modified: Aug 10, 2026
Product
Microsoft / Windows
Vulnerability
Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability
Added to KEV
Nov 14, 2022
Remediate by
Dec 9, 2022
Known ransomware use
No
Summary description
Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features.
Required action
Apply updates per vendor instructions.
Notes
https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-41049; https://nvd.nist.gov/vuln/detail/CVE-2022-41049
Windows Mark of the Web Security Feature Bypass Vulnerability