CVE-2022-41049
published 2022-11-09CVE-2022-41049: Windows Mark of the Web Security Feature Bypass Vulnerability
PriorityP279medium5.4CVSS 3.1
AVNACLPRNUIRSUCNILAL
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-12-09
Exploited in the wild
EPSS
2.48%
82.8th percentile
Windows Mark of the Web Security Feature Bypass Vulnerability
Affected
37 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1507 | < 10.0.10240.19567 | 10.0.10240.19567 |
| microsoft | windows_10_1607 | < 10.0.14393.5501 | 10.0.14393.5501 |
| microsoft | windows_10_1809 | < 10.0.17763.3650 | 10.0.17763.3650 |
| microsoft | windows_10_20h2 | < 10.0.19042.2251 | 10.0.19042.2251 |
| microsoft | windows_10_21h1 | < 10.0.19043.2251 | 10.0.19043.2251 |
| microsoft | windows_10_21h2 | < 10.0.19044.2251 | 10.0.19044.2251 |
| microsoft | windows_10_22h2 | < 10.0.19045.2251 | 10.0.19045.2251 |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.19567 | 10.0.10240.19567 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.5501 | 10.0.14393.5501 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.3650 | 10.0.17763.3650 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.3650 | 10.0.17763.3650 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.2251 | 10.0.19042.2251 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.2251 | 10.0.19043.2251 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.2251 | 10.0.19044.2251 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.2251 | 10.0.19045.2251 |
| microsoft | windows_11_21h2 | < 10.0.22000.1219 | 10.0.22000.1219 |
| microsoft | windows_11_22h2 | < 10.0.22621.819 | 10.0.22621.819 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.1219 | 10.0.22000.1219 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.819 | 10.0.22621.819 |
| microsoft | windows_server_2016 | < 10.0.14393.5501 | 10.0.14393.5501 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.5501 | 10.0.14393.5501 |
| microsoft | windows_server_2019 | < 10.0.17763.3650 | 10.0.17763.3650 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.3650 | 10.0.17763.3650 |
| microsoft | windows_server_2022 | < 10.0.20348.1249 | 10.0.20348.1249 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.1249 | 10.0.20348.1249 |
Detection & IOCsextracted from sources · hover to see the quote
urlhxxps://www.ukrainianworldcongress[.]info/sites/default/files/document/forms/2023/Overview_of_UWCs_UkraineInNATO_campaign.docx↗
- →Detect .docx files containing an altChunk element in word/document.xml that references an external RTF file (e.g., word/afchunk.rtf), which may be used to embed malicious OLE objects and bypass MotW. ↗
- →Detect RTF files containing both objautlink and objupdate control words combined with a Word.Document.8 object class, as this pattern is used to force OLE object updates and trigger SMB/HTTP connections. ↗
- →Monitor for outbound SMB connections (port 445) to external/internet IPs originating from Microsoft Office processes, which may indicate NTLM credential leakage via OLE autolink objects. ↗
- →Detect Office documents that open without Protected View despite being downloaded from the internet, which may indicate successful MotW bypass via CVE-2022-41049. ↗
- ·CVE-2022-41049 is confirmed exploited in the wild (both latest and older software releases), per Microsoft MSRC. Patching is required; the CISA remediation due date was 2022-12-09. ↗
- ·The MotW bypass results in only a limited loss of integrity and availability (CVSS I:L, A:L), but its primary impact is disabling downstream security features such as Protected View in Microsoft Office that depend on MotW tagging. ↗
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
vulncheck5.4MEDIUM
cisa5.4MEDIUM
vendor_msrc5.4MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-ccv7-v4mw-3wqq: Windows Mark of the Web Security Feature Bypass Vulnerability
ghsa_unreviewed·2022-11-10·CVSS 5.4
CVE-2022-41091 [MEDIUM] CWE-863 GHSA-ccv7-v4mw-3wqq: Windows Mark of the Web Security Feature Bypass Vulnerability
Windows Mark of the Web Security Feature Bypass Vulnerability. This CVE ID is unique from CVE-2022-41049.
GHSA
GHSA-wjh3-j799-8ppv: Windows Mark of the Web Security Feature Bypass Vulnerability
ghsa_unreviewed·2022-11-10·CVSS 5.4
CVE-2022-41049 [MEDIUM] GHSA-wjh3-j799-8ppv: Windows Mark of the Web Security Feature Bypass Vulnerability
Windows Mark of the Web Security Feature Bypass Vulnerability. This CVE ID is unique from CVE-2022-41091.
VulnCheck
Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability
vulncheck·2022·CVSS 5.4
CVE-2022-41049 [MEDIUM] CWE-274 Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability
Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability
Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features.
Affected: Microsoft Windows
Required Action: Apply updates per vendor instructions.
Exploitation References: https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2022-Nov; https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41049; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due: 2022-12-09
CISA
Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability
cisa·2022-11-14·CVSS 5.4
CVE-2022-41049 [MEDIUM] CWE-274 Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability
Vulnerability: Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability
Affected: Microsoft Windows
Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features.
Required Action: Apply updates per vendor instructions.
Notes: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-41049; https://nvd.nist.gov/vuln/detail/CVE-2022-41049
Remediation Due Date: 2022-12-09
Microsoft
Windows Mark of the Web Security Feature Bypass Vulnerability
vendor_msrc·2022-11-08·CVSS 5.4
CVE-2022-41049 [MEDIUM] Windows Mark of the Web Security Feature Bypass Vulnerability
Windows Mark of the Web Security Feature Bypass Vulnerability
FAQ: How could an attacker exploit the vulnerability?
In a web-based attack scenario, an attacker could host a malicious website that is designed to exploit the security feature bypass.
In an email or instant message attack scenario, the attacker could send the targeted user a specially crafted .url file that is designed to exploit the bypass.
Compromised websites or websites that accept or host user-provided content could contain specially crafted content to exploit the security feature bypass.
In all cases an attacker would have no way to force a user to view attacker-controlled content. Instead, an attacker would have to convince a user to take action. For example, an attacker could entice a user to either click a link tha
No detection rules found.
No public exploits indexed.
Unit42
In-Depth Analysis of July 2023 Exploit Chain Featuring CVE-2023-36884 and CVE-2023-36584
blogs_unit42·2023-11-13·CVSS 5.4
CVE-2023-36584 [MEDIUM] In-Depth Analysis of July 2023 Exploit Chain Featuring CVE-2023-36884 and CVE-2023-36584
## Executive Summary
During our analysis of a July 2023 campaign targeting groups supporting Ukraine's admission into NATO, we discovered a new vulnerability for bypassing Microsoft's Mark-of-the-Web (MotW) security feature. This activity has been attributed by the community to the pro-Russian APT group known as Storm-0978 (also known as the RomCom Group, in reference to their use of the RomCom backdoor). This group used a highly complex and well-developed exploit chain leveraging a remote code execution (RCE) vulnerability in Microsoft Office designated CVE-2023-36884 to infect its targets with malware.
Our investigation revealed a new exploit method related to CVE-2023-36884 that can bypass MotW. Microsoft awarded our team a bug bounty and assigned CVE-2023-36584 (CVSS score 5) to this
Unit42
In-Depth Analysis of July 2023 Exploit Chain Featuring CVE-2023-36884 and CVE-2023-36584
blogs_unit42·2023-11-13·CVSS 5.4
CVE-2023-36884 [MEDIUM] In-Depth Analysis of July 2023 Exploit Chain Featuring CVE-2023-36884 and CVE-2023-36584
Threat Research Center
Threat Research
Vulnerabilities
## In-Depth Analysis of July 2023 Exploit Chain Featuring CVE-2023-36884 and CVE-2023-36584
Eli Birkan
Dan Yashnik
Oriel Cochavi
Bar Lahav
Mike Harbison
Published: November 13, 2023
Malware
Threat Research
Vulnerabilities
CVE-2023-36584
CVE-2023-36884
Exploit
Microsoft Office
Microsoft Vulnerability
Remote Code Execution
RomCom
Storm-0978
Ukraine
## Executive Summary
During our analysis of a July 2023 campaign targeting groups supporting Ukraine's admission into NATO, we discovered a new vulnerability for bypassing Microsoft's Mark-of-the-Web (MotW) security feature. This activity has been attributed by the community to the pro-Russian APT group known as Storm-0978 (also known as the RomCom Group, in referenc
Tenable
Microsoft’s November 2022 Patch Tuesday Addresses 62 CVEs (CVE-2022-41073)
blogs_tenable·2022-11-08·CVSS 7.8
[HIGH] Microsoft’s November 2022 Patch Tuesday Addresses 62 CVEs (CVE-2022-41073)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
2022-11-09
Published
2022-11-14
Added to CISA KEV
Exploited in the wild