CVE-2022-41091
published 2022-11-09CVE-2022-41091: Windows Mark of the Web Security Feature Bypass Vulnerability
PriorityP184medium5.4CVSS 3.1
AVNACLPRNUIRSUCNILAL
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2022-12-09
Exploited in the wild
EPSS
1.99%
78.4th percentile
Windows Mark of the Web Security Feature Bypass Vulnerability
Affected
37 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1507 | < 10.0.10240.19567 | 10.0.10240.19567 |
| microsoft | windows_10_1607 | < 10.0.14393.5501 | 10.0.14393.5501 |
| microsoft | windows_10_1809 | < 10.0.17763.3650 | 10.0.17763.3650 |
| microsoft | windows_10_20h2 | < 10.0.19042.2251 | 10.0.19042.2251 |
| microsoft | windows_10_21h1 | < 10.0.19043.2251 | 10.0.19043.2251 |
| microsoft | windows_10_21h2 | < 10.0.19044.2251 | 10.0.19044.2251 |
| microsoft | windows_10_22h2 | < 10.0.19045.2251 | 10.0.19045.2251 |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.19567 | 10.0.10240.19567 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.5501 | 10.0.14393.5501 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.3650 | 10.0.17763.3650 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.3650 | 10.0.17763.3650 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.2251 | 10.0.19042.2251 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.2251 | 10.0.19043.2251 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.2251 | 10.0.19044.2251 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.2251 | 10.0.19045.2251 |
| microsoft | windows_11_21h2 | < 10.0.22000.1219 | 10.0.22000.1219 |
| microsoft | windows_11_22h2 | < 10.0.22621.819 | 10.0.22621.819 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.1219 | 10.0.22000.1219 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.819 | 10.0.22621.819 |
| microsoft | windows_server_2016 | < 10.0.14393.5501 | 10.0.14393.5501 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.5501 | 10.0.14393.5501 |
| microsoft | windows_server_2019 | < 10.0.17763.3650 | 10.0.17763.3650 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.3650 | 10.0.17763.3650 |
| microsoft | windows_server_2022 | < 10.0.20348.1249 | 10.0.20348.1249 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.1249 | 10.0.20348.1249 |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for ISO files containing LNK files being executed, as adversaries exploited the MOTW vulnerability in ISO files (CVE-2022-41091) to bypass Mark-of-the-Web protections — files inside ISOs did not receive MOTW when downloaded from the internet. ↗
- ·CVE-2022-41091 affects Microsoft Windows broadly; CISA required remediation by 2022-12-09 per vendor instructions. No specific configuration is required to be vulnerable — the flaw is in how MOTW is applied to files extracted from ISO containers. ↗
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
vulncheck5.4MEDIUM
cisa5.4MEDIUM
vendor_msrc5.4MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-ccv7-v4mw-3wqq: Windows Mark of the Web Security Feature Bypass Vulnerability
ghsa_unreviewed·2022-11-10·CVSS 5.4
CVE-2022-41091 [MEDIUM] CWE-863 GHSA-ccv7-v4mw-3wqq: Windows Mark of the Web Security Feature Bypass Vulnerability
Windows Mark of the Web Security Feature Bypass Vulnerability. This CVE ID is unique from CVE-2022-41049.
GHSA
GHSA-wjh3-j799-8ppv: Windows Mark of the Web Security Feature Bypass Vulnerability
ghsa_unreviewed·2022-11-10·CVSS 5.4
CVE-2022-41049 [MEDIUM] GHSA-wjh3-j799-8ppv: Windows Mark of the Web Security Feature Bypass Vulnerability
Windows Mark of the Web Security Feature Bypass Vulnerability. This CVE ID is unique from CVE-2022-41091.
VulnCheck
Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability
vulncheck·2022·CVSS 5.4
CVE-2022-41091 [MEDIUM] CWE-863 Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability
Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability
Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features.
Affected: Microsoft Windows
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2022-Nov; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.welivesecurity.com/wp-content/uploads/2023/01/eset_apt_activity_report_t32022.pdf; https://info.securin.io/hubfs/Securin%20Ransomware%20Report%202023.pdf; https://go.recordedfuture.com/hubfs/reports/ta-2023-0302.pdf; https://www.mandiant.com/resou
CISA
Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability
cisa·2022-11-08·CVSS 5.4
CVE-2022-41091 [MEDIUM] CWE-863 Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability
Vulnerability: Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability
Affected: Microsoft Windows
Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features.
Required Action: Apply updates per vendor instructions.
Notes: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-41091; https://nvd.nist.gov/vuln/detail/CVE-2022-41091
Remediation Due Date: 2022-12-09
Microsoft
Windows Mark of the Web Security Feature Bypass Vulnerability
vendor_msrc·2022-11-08·CVSS 5.4
CVE-2022-41091 [MEDIUM] Windows Mark of the Web Security Feature Bypass Vulnerability
Windows Mark of the Web Security Feature Bypass Vulnerability
FAQ: How could an attacker exploit the vulnerability?
In a web-based attack scenario, an attacker could host a malicious website that is designed to exploit the security feature bypass.
In an email or instant message attack scenario, the attacker could send the targeted user a specially crafted .url file that is designed to exploit the bypass.
Compromised websites or websites that accept or host user-provided content could contain specially crafted content to exploit the security feature bypass.
In all cases an attacker would have no way to force a user to view attacker-controlled content. Instead, an attacker would have to convince a user to take action. For example, an attacker could entice a user to either click a link tha
No detection rules found.
No public exploits indexed.
Greynoiseio
The Noise in the Silence: Unmasking CISA's Hidden KEV Ransomware Updates
blogs_greynoiseio·2026-02-02
The Noise in the Silence: Unmasking CISA's Hidden KEV Ransomware Updates
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Qualys
Qualys Threat Research Unit: Threat Thursdays, December 2022
blogs_qualys·2022-12-29
Qualys Threat Research Unit: Threat Thursdays, December 2022
## Table of Contents
From the Qualys Blogs
New Tools & Techniques
New Vulnerabilities
Threat Thursdays Webinar
Welcome to the fourth edition of the Qualys Threat Research Unit’s (TRU) “Threat Research Thursday”, where we collect and curate notable new tools, techniques, procedures, threat intelligence, cybersecurity news, malware attacks, and more. This also happens to be the last edition for the year. Feedback on our third edition, Qualys Threat Research Thursday , is more than welcome. We would love to hear from you!
## From the Qualys Blogs
Here is a roundup of the most interesting blogs from the Qualys Research Team over the past couple of weeks:
Dissecting the Empire C2 Framework – In this blog post, we take a quick dive into Empire, a popular open-source post-exploitation fra
Qualys
Qualys Threat Research Unit: Threat Thursdays, December 2022 | Qualys
blogs_qualys·2022-12-29
Qualys Threat Research Unit: Threat Thursdays, December 2022 | Qualys
#### Table of Contents
- From the Qualys Blogs
- New Tools & Techniques
- New Vulnerabilities
- Threat Thursdays Webinar
Welcome to the fourth edition of the Qualys Threat Research Unit’s (TRU) “Threat Research Thursday”, where we collect and curate notable new tools, techniques, procedures, threat intelligence, cybersecurity news, malware attacks, and more. This also happens to be the last edition for the year. Feedback on our third edition, Qualys Threat Research Thursday, is more than welcome. We would love to hear from you!
## From the Qualys Blogs
Here is a roundup of the most interesting blogs from the Qualys Research Team over the past couple of weeks:
- Dissecting the Empire C2 Framework – In this blog post, we take a quick dive into Empire, a popular open-source post-exploita
Qualys
The December 2022 Patch Tuesday Security Update Review | Qualys
blogs_qualys·2022-12-13·CVSS 7.8
CVE-2022-41089 [HIGH] The December 2022 Patch Tuesday Security Update Review | Qualys
#### Table of Contents
- Microsoft Patches for December 2022
- Adobe Patches for December 2022
- Notable Microsoft Vulnerabilities Patched
- Microsoft Critical Vulnerability Highlights
- CVE-2022-41089 | .NET Framework Remote Code Execution Vulnerability
- Microsoft Release Summary
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- EXECUTE Mitigation Using Qualys Custom Assessment and Remediation (CAR)
- EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
- Qualys Monthly Webinar Series
- This Month in Vulnerabilities & Patches
Welcome to the final second Tuesday of the year. As expected, Microsoft and Adobe have released their latest security updates and fixes. Take a break from your holiday preparations and join us as we re
Qualys
The December 2022 Patch Tuesday Security Update Review
blogs_qualys·2022-12-13·CVSS 7.8
CVE-2022-41089 [HIGH] The December 2022 Patch Tuesday Security Update Review
## Table of Contents
Microsoft Patches for December 2022
Adobe Patches for December 2022
Notable Microsoft Vulnerabilities Patched
Microsoft Critical Vulnerability Highlights
CVE-2022-41089 | .NET Framework Remote Code Execution Vulnerability
Microsoft Release Summary
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
EXECUTE Mitigation Using Qualys Custom Assessment and Remediation (CAR)
EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
Qualys Monthly Webinar Series
This Month in Vulnerabilities & Patches
Welcome to the final second Tuesday of the year. As expected, Microsoft and Adobe have released their latest security updates and fixes. Take a break from your holiday preparations and join us as we review the detai
Krebs
Patch Tuesday, November 2022 Election Edition
blogs_krebs·2022-11-09·CVSS 7.8
[HIGH] Patch Tuesday, November 2022 Election Edition
Let’s face it: Having “2022 election” in the headline above is probably the only reason anyone might read this story today. Still, while most of us here in the United States are anxiously awaiting the results of how well we’ve patched our Democracy, it seems fitting that Microsoft Corp. today released gobs of security patches for its ubiquitous Windows operating systems. November’s patch batch includes fixes for a whopping six zero-day security vulnerabilities that miscreants and malware are already exploiting in the wild.
Probably the scariest of the zero-day flaws is CVE-2022-41128 , a “critical” weakness in the Windows scripting languages that could be used to foist malicious software on vulnerable users who do nothing more than browse to a hacked or malicious site that exploits the we
Krebs
Patch Tuesday, November 2022 Election Edition
blogs_krebs·2022-11-09·CVSS 7.8
[HIGH] Patch Tuesday, November 2022 Election Edition
Let’s face it: Having “2022 election” in the headline above is probably the only reason anyone might read this story today. Still, while most of us here in the United States are anxiously awaiting the results of how well we’ve patched our Democracy, it seems fitting that Microsoft Corp. today released gobs of security patches for its ubiquitous Windows operating systems. November’s patch batch includes fixes for a whopping six zero-day security vulnerabilities that miscreants and malware are already exploiting in the wild.
Probably the scariest of the zero-day flaws is CVE-2022-41128, a “critical” weakness in the Windows scripting languages that could be used to foist malicious software on vulnerable users who do nothing more than browse to a hacked or malicious site that exploits the wea
Qualys
November 2022 Patch Tuesday | Microsoft Releases 65 New Vulnerabilities With 10 Critical; Adobe Releases Zero Advisories (for the First Time in Six Years).
blogs_qualys·2022-11-08·CVSS 7.5
[HIGH] November 2022 Patch Tuesday | Microsoft Releases 65 New Vulnerabilities With 10 Critical; Adobe Releases Zero Advisories (for the First Time in Six Years).
## Table of Contents
Microsoft Patch Tuesday Summary
The November 2022 Microsoft Vulnerabilities are Classified as Follows:
OpenSSL 3.x Critical Vulnerability Highlights
OpenSSL 3.x Related Blogs and Resources
Microsoft Addressed Six Zero-Day Vulnerabilities
Microsoft Patch Tuesday Critical Vulnerability Highlights
Microsoft Release Summary
Adobe Security Bulletins and Advisories
About Qualys Patch Tuesday
Qualys Threat Research Blog Posts
Qualys Threat Protection High-Rated Advisories
Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response(VMDR)
Rapid Response with Patch Management (PM)
Extend the Power of VMDR to Enterprise Mobile Devices With Qualys VMDR Mobile
Execute Mitigation UsingCustom Assessment and Remediation(CAR)
Patch Tuesday Is
Talos
Microsoft Patch Tuesday for November 2022 — Snort rules and prominent vulnerabilities
blogs_talos·2022-11-08·CVSS 8.1
CVE-2022-41039 [HIGH] Microsoft Patch Tuesday for November 2022 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for November 2022 — Snort rules and prominent vulnerabilities
Microsoft released its monthly security update on Tuesday, disclosing 62 vulnerabilities. Of these vulnerabilities, 8 are classified as “Critical” and the rest are classified as “Important.”
Three of the critical entries are remote code execution (RCE) vulnerabilities for Windows Point-to-Point Tunneling Protocol (PPTP).
CVE-2022-41039
CVE-2022-41044
CVE-2022-41088
An unauthenticated attacker can send a specially crafted request to an RAS (Remote Access Server), which may lead to remote code execution. Although according to Microsoft, these three vulnerabilities are less likely to be exploited, as the attacker must win a complex race condition. In August of 2022’s Patch Tuesday release, several v
Tenable
Microsoft’s November 2022 Patch Tuesday Addresses 62 CVEs (CVE-2022-41073)
blogs_tenable·2022-11-08·CVSS 7.8
[HIGH] Microsoft’s November 2022 Patch Tuesday Addresses 62 CVEs (CVE-2022-41073)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
November 2022 Patch Tuesday | Microsoft Releases 65 New Vulnerabilities With 10 Critical; Adobe Releases Zero Advisories (for the First Time in Six Years). | Qualys
blogs_qualys·2022-11-08·CVSS 7.5
[HIGH] November 2022 Patch Tuesday | Microsoft Releases 65 New Vulnerabilities With 10 Critical; Adobe Releases Zero Advisories (for the First Time in Six Years). | Qualys
#### Table of Contents
- Microsoft Patch Tuesday Summary
- The November 2022 Microsoft Vulnerabilities are Classified as Follows:
- OpenSSL 3.x Critical Vulnerability Highlights
- OpenSSL 3.x Related Blogs and Resources
- Microsoft Addressed Six Zero-Day Vulnerabilities
- Microsoft Patch Tuesday Critical Vulnerability Highlights
- Microsoft Release Summary
- Adobe Security Bulletins and Advisories
- About Qualys Patch Tuesday
- Qualys Threat Research Blog Posts
- Qualys Threat Protection High-Rated Advisories
- Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response(VMDR)
- Rapid Response with Patch Management (PM)
- Extend the Power of VMDR to Enterprise Mobile Devices With Qualys VMDR Mobile
- Execute Mitigation UsingCustom Assessment and Remediation(CAR)
Talos
Microsoft Patch Tuesday for November 2022 — Snort rules and prominent vulnerabilities
blogs_talos·2022-11-08·CVSS 8.1
CVE-2022-41039 [HIGH] Microsoft Patch Tuesday for November 2022 — Snort rules and prominent vulnerabilities
Microsoft released its monthly security update on Tuesday, disclosing 62 vulnerabilities. Of these vulnerabilities, 8 are classified as “Critical” and the rest are classified as “Important.”
Three of the critical entries are remote code execution (RCE) vulnerabilities for Windows Point-to-Point Tunneling Protocol (PPTP).
- CVE-2022-41039
- CVE-2022-41044
- CVE-2022-41088
An unauthenticated attacker can send a specially crafted request to an RAS (Remote Access Server), which may lead to remote code execution. Although according to Microsoft, these three vulnerabilities are less likely to be exploited, as the attacker must win a complex race condition. In August of 2022’s Patch Tuesday release, several vulnerabilities for Windows PPTP were also disclosed.
Another notable vulnerability in
Crowdstrike
OneNote to Rule them All: eCrime Adversaries Adopt OneNote for Distribution
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] OneNote to Rule them All: eCrime Adversaries Adopt OneNote for Distribution
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Crowdstrike
OneNote to Rule them All: eCrime Adversaries Adopt OneNote for Distribution
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] OneNote to Rule them All: eCrime Adversaries Adopt OneNote for Distribution
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
Crowdstrike
November 2022 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] November 2022 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
arXiv
Vulnerability Management Chaining: An Integrated Framework for Efficient Cybersecurity Risk Prioritization
arxiv_fulltext·2025-07-10
Vulnerability Management Chaining: An Integrated Framework for Efficient Cybersecurity Risk Prioritization
## Abstract
As the number of Common Vulnerabilities and Exposures (CVE) continues to grow exponentially, security teams face increasingly difficult decisions about prioritization. Current approaches using Common Vulnerability Scoring System (CVSS) scores produce overwhelming volumes of high-priority vulnerabilities, while Exploit Prediction Scoring System (EPSS) and Known Exploited Vulnerabilities (KEV) catalog offer valuable but incomplete perspectives on actual exploitation risk. We present Vulnerability Management Chaining, a decision tree framework that systematically integrates these three approaches to achieve efficient vulnerability prioritization. Our framework employs a two-stage evaluation process: first applying threat-based filtering using KEV membership or EPSS threshold 0.08
arXiv
On the Abuse and Detection of Polyglot Files
arxiv_fulltext·2024-07-01
On the Abuse and Detection of Polyglot Files
Notice: This manuscript has been authored [or, co-authored] by UT-Battelle, LLC, under contract DE-AC05-00OR22725 with the US Department of Energy (DOE). The US government retains and the publisher, by accepting the article for publication, acknowledges that the US government retains a nonexclusive, paid-up, irrevocable, worldwide license to publish or reproduce the published form of this manuscript, or allow others to do so, for US government purposes. DOE will provide public access to these results of federally sponsored research in accordance with the DOE Public Access Plan (http://energy.gov/downloads/doe-public-access-plan).
## Abstract
A polyglot is a file that is valid in two or more formats. Polyglot files pose a problem for malware detection systems that route files
to format-sp
2022-11-09
Published
2022-11-08
Added to CISA KEV
Exploited in the wild