CVE-2022-41091
Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability
CVSS
5.4
Medium
EPSS
1.9%
p78
KEV
YES
Nov 8, 2022
Exploit Today
74
0-100
Published: Nov 9, 2022 · Last modified: Aug 10, 2026 · CWE-863
Product
Microsoft / Windows
Vulnerability
Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability
Added to KEV
Nov 8, 2022
Remediate by
Dec 9, 2022
Known ransomware use
Yes
Summary description
Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features.
Required action
Apply updates per vendor instructions.
Notes
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-41091; https://nvd.nist.gov/vuln/detail/CVE-2022-41091
Windows Mark of the Web Security Feature Bypass Vulnerability