CVE detail
CVE-2022-41091
Windows Mark of the Web Security Feature Bypass Vulnerability
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 24.0 · diversity 19.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
10 source links · newest first
Deploying security patches as quickly as possible remains one of the best ways to prevent most security breaches, as attackers usually rely on exploits for publicly known vulnerabilities that have a patch available — the so-called n-day exploits. But mitigating the risk from vulnerabilities unknown to the affected software developers and don’t have a patch […]
newswww.csoonline.comMar 22, 2023, 7:38 PMMandiant has conducted an analysis of the zero-day vulnerabilities disclosed in 2022 and over a dozen were linked to cyberespionage groups.
newswww.securityweek.comMar 21, 2023, 1:13 PM- Week in review: Microsoft fixes many zero-days, malicious droppers on Google Play, IRISSCON 2022Help Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Taking cybersecurity investments to the next level In this Help Net Security interview, the former Trident Capital leader offers insight into innovation in the cybersecurity market, M&A activity, pitching to VCs, and more. Microsoft fixes many zero-days under attack November 2022 Patch Tuesday is here, with fixes for many vulnerabilities actively exploited in the wild, including CVE-2022-41091, a Windows Mark … More →
newswww.helpnetsecurity.comNov 13, 2022, 9:00 AM No excerpt available.
Mitigationwww.cisa.govNov 9, 2022, 10:15 PM- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41091msrc.microsoft.com
No excerpt available.
Vendor Advisorymsrc.microsoft.comNov 9, 2022, 10:15 PM Microsoft’s latest Patch Tuesday updates address six zero-day vulnerabilities, including one related to the Mark-of-the-Web (MotW) security feature that has been exploited by cybercriminals to deliver malware.
newswww.securityweek.comNov 9, 2022, 7:18 PMMicrosoft Patch Tuesday updates for November 2022 addressed 64 vulnerabilities, including six actively exploited zero-days. Microsoft Patch Tuesday updates for November 2022 addressed 64 new vulnerabilities in Microsoft Windows and Windows Components; Azure and Azure Real Time Operating System; Microsoft Dynamics; Exchange Server; Office and Office Components; SysInternals; Visual Studio; SharePoint Server; Network Policy Server […]
newssecurityaffairs.comNov 9, 2022, 11:54 AMSoftware security platform Rezilion has expanded its Dynamic Software Bill of Materials (SBOM) capability to support Windows environments. The firm said the move will provide organizations with the tools to efficiently manage software vulnerabilities and meet new regulatory standards, addressing functionality gaps of traditional vulnerability management tools primarily designed for use with Linux OS. Features […]
newswww.csoonline.comNov 9, 2022, 11:00 AM- Microsoft fixes many zero-days under attackHelp Net Security
November 2022 Patch Tuesday is here, with fixes for many vulnerabilities actively exploited in the wild, including CVE-2022-41091, a Windows Mark of the Web bypass flaw, and the ProxyNotShell MS Exchange vulnerabilities. Fixes to prioritize CVE-2022-41091 is a Windows zero-day vulnerability that allows attackers to bypass the Mark of the Web (MOTW) security feature. They can craft a malicious file triggering the flaw and deliver it either via a malicious or compromised website or via … More →
newswww.helpnetsecurity.comNov 8, 2022, 7:53 PM The zero-day attacks against Microsoft’s software products are showing no signs of slowing down.
newswww.securityweek.comNov 8, 2022, 6:40 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2023-24932CVSS 6.7 · Medium
Secure Boot Security Feature Bypass Vulnerability
- CVE-2023-28249CVSS 6.2 · Medium
Windows Boot Manager Security Feature Bypass Vulnerability
- CVE-2024-7553CVSS 7.3 · High
Incorrect validation of files loaded from a local untrusted directory may allow local privilege escalation if the underlying operating systems is Windows. This may result in the a…
- CVE-2023-21808CVSS 7.8 · High
.NET and Visual Studio Remote Code Execution Vulnerability
- CVE-2023-21722CVSS 5.0 · Medium
.NET Framework Denial of Service Vulnerability
- CVE-2022-41128CVSS 8.8 · High
Windows Scripting Languages Remote Code Execution Vulnerability