LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-44698: Microsoft Defender SmartScreen Security Feature Bypass Vulnerability

RBRecent Breaches Vulnerability Intelligence·Dec 13, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Jan 3, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-44698 to its Known Exploited Vulnerabilities catalog on Dec 13, 2022, with a federal patch deadline of Jan 3, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Microsoft Defender SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file.

CVE-2022-44698 is a security feature bypass in Microsoft Defender SmartScreen. It lets an attacker evade Mark of the Web (MOTW) protections by using a specially crafted malicious file. Because MOTW is a common Windows defense that flags files from the internet and triggers extra scrutiny, a bypass can reduce the chance that users or automated controls will block or warn about untrusted content. CISA notes known ransomware use of this vulnerability, so organizations that rely on SmartScreen and MOTW should treat it as a priority for inventory and remediation.

Public detail is limited to the CISA summary and the CWE classification; exact affected builds, scoring, and exploit mechanics must be confirmed against the Microsoft vendor advisory. The required action is to apply updates per vendor instructions.

How it works

The weakness is classified as CWE-755 (Improper Handling of Exceptional Conditions). In this class of flaw, the product does not correctly handle an unexpected or crafted condition, allowing security logic to be skipped or weakened. Here, SmartScreen’s MOTW-related checks can be bypassed when the attacker supplies a specially crafted malicious file. An attacker who can deliver such a file (for example via download, email attachment, or other user-initiated transfer) may cause the system to treat the file without the full MOTW protections that would otherwise apply. The result is reduced visibility and fewer automatic blocks or prompts that defenders normally rely on. No further exploit mechanics are provided in the available facts; treat any public proof-of-concept claims cautiously and validate against the vendor advisory.

Am I affected? How to find it in your systems

Microsoft Defender SmartScreen is a Windows component commonly present on client and some server endpoints that use Microsoft Defender. It participates in MOTW handling for files originating from the internet or other untrusted zones. Inventory all Windows systems that have Microsoft Defender enabled and that process user-downloaded or externally sourced files.

How to remediate

Patch first. Apply the Microsoft updates that address CVE-2022-44698 exactly as directed in the vendor advisory. CISA’s required action is to apply updates per vendor instructions; follow Microsoft’s guidance for deployment order, reboots, and verification.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls that do not depend solely on SmartScreen MOTW checks.

If your data may have been exposed

Actively exploited vulnerabilities, including those with known ransomware use, can lead to compromise and data exposure. If you suspect exploitation, isolate affected hosts, preserve forensic evidence, and follow your incident-response process. You can also run a free exposure scan of your email addresses against known breach data to check whether credentials or personal information have already appeared in public dumps, then force password resets and enable multi-factor authentication where accounts may be at risk.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Defender
WeaknessCWE-755
Added to CISA KEVDec 13, 2022
Federal patch deadlineJan 3, 2023
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities