Vulnerability record · CVE-2022-41128 · published 9 November 2022
CVE-2022-41128: Windows Scripting Languages out-of-bounds write allows remote code execution
Microsoft · Windows 10 1507
CVE-2022-41128 is an out-of-bounds write (CWE-787) in Windows Scripting Languages that leads to remote code execution. Microsoft rates it 8.8 HIGH with a network vector, and CISA added it to the Known Exploited Vulnerabilities catalog, so it is being exploited in the wild. It affects a broad set of Windows client and server releases, making unpatched fleets a live target.
Description
Windows Scripting Languages Remote Code Execution Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
critical priorityIt is a network-reachable remote code execution flaw with a CISA KEV listing and very high EPSS score, so it is actively exploited and must be patched urgently.
What it is
CVE-2022-41128 is an out-of-bounds write (CWE-787) in Windows Scripting Languages that leads to remote code execution. Microsoft rates it 8.8 HIGH with a network vector, and CISA added it to the Known Exploited Vulnerabilities catalog, so it is being exploited in the wild. It affects a broad set of Windows client and server releases, making unpatched fleets a live target.
Impact
An attacker who gets code to run in the scripting engine can execute arbitrary code in the context of the affected process, giving full compromise of confidentiality, integrity and availability on the host.
Attack surface
Reached over the network (AV:N) with no privileges required (PR:N), but exploitation requires user interaction (UI:R), consistent with a victim opening or rendering attacker-supplied content that invokes the scripting engine. No other reachability detail is given in the record.
Exploitation
Listed in CISA KEV with an added date of 2022-11-08 and a remediation due date of 2022-12-09, and EPSS 30-day probability is 0.24623 (97.8th percentile), indicating active exploitation and high likelihood. The record does not state whether ransomware campaigns use it.
What to do
- Apply the Microsoft updates referenced in the MSRC advisory for CVE-2022-41128 across all affected Windows client and server versions.
- Prioritize internet-facing and user-workstation systems, and meet the CISA KEV due date of 2022-12-09.
- Reduce exposure by restricting execution of untrusted script content and blocking delivery of malicious documents or web content where feasible.
- Verify patch coverage against the full affected product list, including older releases such as Windows 7, 8.1 and Server 2008/2012.
- Monitor for exploitation attempts and treat unpatched hosts as compromised until triaged.
Detection
- Hunt for suspicious child processes spawned by Windows scripting hosts (wscript.exe, cscript.exe, mshta.exe) and for script engines loading unusual modules.
- Alert on scripting-engine crashes or memory-corruption indicators on endpoints running unpatched Windows builds.
- Review email, web and file-transfer logs for delivery of documents or content that trigger the scripting engine around the KEV exploitation window.
- Correlate endpoint telemetry for post-exploitation behavior from scripting processes, such as network connections or credential access.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-41128 to the Known Exploited Vulnerabilities catalog on 8 November 2022 as "Microsoft Windows Scripting Languages Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 9 December 2022.
Affected products
16 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41128 | PatchVendor Advisory |
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41128 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-41128 | US Government Resource |
Track CVE-2022-41128 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-41128), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.