CVE detail
CVE-2022-41049
Windows Mark of the Web Security Feature Bypass Vulnerability
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 17.9 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
5 source links · newest first
In July 2023, pro-Russian APT Storm-0978 targeted support for Ukrainian NATO admission with an exploit chain. Analysis of it reveals the new CVE-2023-36584.
vendorunit42.paloaltonetworks.comNov 13, 2023, 11:00 AMNo excerpt available.
Mitigationwww.cisa.govNov 9, 2022, 10:15 PM- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41049msrc.microsoft.com
No excerpt available.
Vendor Advisorymsrc.microsoft.comNov 9, 2022, 10:15 PM Microsoft’s latest Patch Tuesday updates address six zero-day vulnerabilities, including one related to the Mark-of-the-Web (MotW) security feature that has been exploited by cybercriminals to deliver malware.
newswww.securityweek.comNov 9, 2022, 7:18 PM- Microsoft fixes many zero-days under attackHelp Net Security
November 2022 Patch Tuesday is here, with fixes for many vulnerabilities actively exploited in the wild, including CVE-2022-41091, a Windows Mark of the Web bypass flaw, and the ProxyNotShell MS Exchange vulnerabilities. Fixes to prioritize CVE-2022-41091 is a Windows zero-day vulnerability that allows attackers to bypass the Mark of the Web (MOTW) security feature. They can craft a malicious file triggering the flaw and deliver it either via a malicious or compromised website or via … More →
newswww.helpnetsecurity.comNov 8, 2022, 7:53 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2024-7553CVSS 7.3 · High
Incorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underlying operating systems is Windows. This may result in the a…
- CVE-2023-21808CVSS 7.8 · High
.NET and Visual Studio Remote Code Execution Vulnerability
- CVE-2023-21722CVSS 5.0 · Medium
.NET Framework Denial of Service Vulnerability
- CVE-2022-41128CVSS 8.8 · High
Windows Scripting Languages Remote Code Execution Vulnerability
- CVE-2022-41125CVSS 7.8 · High
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability
- CVE-2022-41091CVSS 5.4 · Medium
Windows Mark of the Web Security Feature Bypass Vulnerability