cbcvebase.
CVE-2022-41049
published 2022-11-09

CVE-2022-41049: Windows Mark of the Web Security Feature Bypass Vulnerability

PriorityP279medium5.4CVSS 3.1
AVNACLPRNUIRSUCNILAL
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-12-09
Exploited in the wild
EPSS
2.48%
82.8th percentile
Windows Mark of the Web Security Feature Bypass Vulnerability

Affected

37 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10_1507< 10.0.10240.1956710.0.10240.19567
microsoftwindows_10_1607< 10.0.14393.550110.0.14393.5501
microsoftwindows_10_1809< 10.0.17763.365010.0.17763.3650
microsoftwindows_10_20h2< 10.0.19042.225110.0.19042.2251
microsoftwindows_10_21h1< 10.0.19043.225110.0.19043.2251
microsoftwindows_10_21h2< 10.0.19044.225110.0.19044.2251
microsoftwindows_10_22h2< 10.0.19045.225110.0.19045.2251
microsoftwindows_10_version_1507>= 10.0.10240.0 < 10.0.10240.1956710.0.10240.19567
microsoftwindows_10_version_1607>= 10.0.14393.0 < 10.0.14393.550110.0.14393.5501
microsoftwindows_10_version_1809>= 10.0.0 < 10.0.17763.365010.0.17763.3650
microsoftwindows_10_version_1809>= 10.0.17763.0 < 10.0.17763.365010.0.17763.3650
microsoftwindows_10_version_20h2>= 10.0.0 < 10.0.19042.225110.0.19042.2251
microsoftwindows_10_version_21h1>= 10.0.0 < 10.0.19043.225110.0.19043.2251
microsoftwindows_10_version_21h2>= 10.0.19043.0 < 10.0.19044.225110.0.19044.2251
microsoftwindows_10_version_22h2>= 10.0.19045.0 < 10.0.19045.225110.0.19045.2251
microsoftwindows_11_21h2< 10.0.22000.121910.0.22000.1219
microsoftwindows_11_22h2< 10.0.22621.81910.0.22621.819
microsoftwindows_11_version_21h2>= 10.0.0 < 10.0.22000.121910.0.22000.1219
microsoftwindows_11_version_22h2>= 10.0.22621.0 < 10.0.22621.81910.0.22621.819
microsoftwindows_server_2016< 10.0.14393.550110.0.14393.5501
microsoftwindows_server_2016>= 10.0.14393.0 < 10.0.14393.550110.0.14393.5501
microsoftwindows_server_2019< 10.0.17763.365010.0.17763.3650
microsoftwindows_server_2019>= 10.0.17763.0 < 10.0.17763.365010.0.17763.3650
microsoftwindows_server_2022< 10.0.20348.124910.0.20348.1249
microsoftwindows_server_2022>= 10.0.20348.0 < 10.0.20348.124910.0.20348.1249

Detection & IOCsextracted from sources · hover to see the quote

hasha61b2eafcf39715031357df6b01e85e0d1ea2e8ee1dfec241b114e18f7a1163f
urlhxxps://www.ukrainianworldcongress[.]info/sites/default/files/document/forms/2023/Overview_of_UWCs_UkraineInNATO_campaign.docx
domainukrainianworldcongress[.]info
ip104.234.239[.]26
ip74.50.94[.]156
urlhxxp://74.50.94[.]156/MSHTML_C7/start.xml
path\\104.234.239[.]26\share1\MSHTML_C7\file001.url
pathfile[:]//104.234.239[.]26/share1/MSHTML_C7/1/__file001.htm?d=__
filenameOverview_of_UWCs_UkraineInNATO_campaign.docx
filenameafchunk.rtf
filename2222.chm
filenamefile001.zip
  • Detect .docx files containing an altChunk element in word/document.xml that references an external RTF file (e.g., word/afchunk.rtf), which may be used to embed malicious OLE objects and bypass MotW.
  • Detect RTF files containing both objautlink and objupdate control words combined with a Word.Document.8 object class, as this pattern is used to force OLE object updates and trigger SMB/HTTP connections.
  • Monitor for outbound SMB connections (port 445) to external/internet IPs originating from Microsoft Office processes, which may indicate NTLM credential leakage via OLE autolink objects.
  • Detect Office documents that open without Protected View despite being downloaded from the internet, which may indicate successful MotW bypass via CVE-2022-41049.
  • ·CVE-2022-41049 is confirmed exploited in the wild (both latest and older software releases), per Microsoft MSRC. Patching is required; the CISA remediation due date was 2022-12-09.
  • ·The MotW bypass results in only a limited loss of integrity and availability (CVSS I:L, A:L), but its primary impact is disabling downstream security features such as Protected View in Microsoft Office that depend on MotW tagging.

CVSS provenance

nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
vulncheck5.4MEDIUM
cisa5.4MEDIUM
vendor_msrc5.4MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.