LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-41091: Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 8, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Dec 9, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-41091 to its Known Exploited Vulnerabilities catalog on Nov 8, 2022, with a federal patch deadline of Dec 9, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features.

CVE-2022-41091 is a security feature bypass in Microsoft Windows that affects the Mark of the Web (MOTW) mechanism. MOTW is intended to flag files originating from the internet so that Windows and applications can apply extra protections. This flaw allows that protection to be bypassed, producing a limited loss of integrity and availability of those security features. Because the vulnerability has been used by ransomware operators, organizations running Windows should treat it as a priority for inventory and remediation.

Defenders need a clear picture of how the bypass works, how to locate affected systems, and what to do if patching cannot happen immediately. All version-specific and configuration details must be confirmed against the Microsoft vendor advisory.

How it works

The underlying weakness is CWE-863 (Incorrect Authorization). MOTW relies on zone identifiers and related metadata to decide whether a file should be treated as untrusted. When the authorization check that enforces those restrictions fails or can be circumvented, an attacker who can deliver a file to the system may cause Windows or applications to process it without the expected MOTW-based safeguards.

In practical terms, an adversary typically needs a way to place a specially crafted file on the target (for example through email, download, or other file-transfer paths). Once the bypass succeeds, features that normally block or sandbox internet-sourced content may not activate. The CISA summary describes the impact as limited loss of integrity and availability of security features; exact exploitation mechanics and preconditions must be taken from the vendor advisory rather than assumed.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Windows. MOTW is a core Windows security feature, so any Windows endpoint or server that processes files from external sources is potentially in scope. Confirm exact builds and editions against the Microsoft advisory for CVE-2022-41091.

Because public detail on exact vulnerable builds is limited here, treat every Windows instance as potentially affected until the vendor list is checked.

How to remediate

The primary action is to apply the security updates Microsoft released for this CVE. CISA’s required action is to apply updates per vendor instructions. Deploy the patches through your normal Windows Update, WSUS, or enterprise management channel and verify installation with build-number checks.

Reboot as required by the update and confirm the system reports the fixed state listed in the advisory.

If you can't patch immediately

Until the vendor update can be installed, reduce exposure with compensating controls:

These measures do not replace the patch; they only lower risk until the update is applied.

If your data may have been exposed

Actively exploited vulnerabilities, including those known to be used by ransomware, frequently lead to data theft or encryption. If you have evidence of successful exploitation or unexplained file activity, treat the incident as a potential breach: isolate affected hosts, preserve logs, and follow your incident-response plan. As an additional check, you can run a free exposure scan of your email addresses against known breach data to see whether credentials or personal information have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-863
Added to CISA KEVNov 8, 2022
Federal patch deadlineDec 9, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities