Vulnerability record · CVE-2022-41091 · published 9 November 2022
CVE-2022-41091: Windows Mark of the Web security feature bypass
Microsoft · Windows 10 1507
Windows Mark of the Web (MOTW) fails to correctly enforce its authorization check, allowing a crafted file to bypass the MOTW tag that normally flags files downloaded from the internet. Because MOTW drives warnings and Protected View/Office macro restrictions, bypassing it weakens a key defense against malicious documents and scripts. Microsoft rates it medium (CVSS 5.4), but CISA lists it as exploited in the wild.
Description
Windows Mark of the Web Security Feature Bypass Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
Automated analysis
high priorityIt is confirmed exploited and linked to ransomware campaigns per CISA KEV, though the CVSS impact is only medium and user interaction is required.
What it is
Windows Mark of the Web (MOTW) fails to correctly enforce its authorization check, allowing a crafted file to bypass the MOTW tag that normally flags files downloaded from the internet. Because MOTW drives warnings and Protected View/Office macro restrictions, bypassing it weakens a key defense against malicious documents and scripts. Microsoft rates it medium (CVSS 5.4), but CISA lists it as exploited in the wild.
Impact
An attacker can get a malicious file to open without the MOTW warning or the restrictions that depend on it, increasing the chance a user runs hostile content. The direct impact per the vector is limited integrity and availability loss, not code execution by itself.
Attack surface
Reached over the network with no privileges required, but user interaction is required (UI:R) — typically the victim opening a crafted file or document. No authentication is needed.
Exploitation
CISA added it to the KEV catalog on 2022-11-08 with a 2022-12-09 remediation due date and flags known ransomware campaign use, so exploitation is confirmed. EPSS is low at roughly 1.8% (77th percentile), and references are patch and government advisory only.
What to do
- Apply the Microsoft update for CVE-2022-41091 to all listed Windows 10, Windows 11 and Windows Server versions.
- Prioritize patching per the CISA KEV due date of 2022-12-09 given confirmed exploitation and ransomware use.
- Keep Protected View, Office macro blocking and attachment sandboxing enabled as compensating controls.
- Block or quarantine risky attachment types at the mail and web gateways.
- Track unpatched endpoints against the affected product list and remediate them first.
Detection
- Alert on files written with a missing or stripped Zone.Identifier alternate data stream.
- Monitor for Office or script processes spawning from user download or temp directories.
- Review endpoint and email logs for MOTW-related bypass activity around the KEV exploitation window.
- Correlate suspicious document execution with ransomware precursor behavior on the same host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-41091 to the Known Exploited Vulnerabilities catalog on 8 November 2022 as "Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 9 December 2022.
Affected products
12 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41091 | PatchVendor Advisory |
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41091 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-41091 | US Government Resource |
Track CVE-2022-41091 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-41091), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.