cbcvebase.
CVE-2022-41128
published 2022-11-09

CVE-2022-41128: Windows Scripting Languages Remote Code Execution Vulnerability

PriorityP187high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-12-09
Exploited in the wild
EPSS
24.62%
97.6th percentile
Windows Scripting Languages Remote Code Execution Vulnerability

Affected

52 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10_1507< 10.0.10240.1956710.0.10240.19567
microsoftwindows_10_1607< 10.0.14393.550110.0.14393.5501
microsoftwindows_10_1809< 10.0.17763.365010.0.17763.3650
microsoftwindows_10_20h2< 10.0.19042.225110.0.19042.2251
microsoftwindows_10_21h1< 10.0.19043.225110.0.19043.2251
microsoftwindows_10_21h2< 10.0.19044.225110.0.19044.2251
microsoftwindows_10_22h2< 10.0.19045.225110.0.19045.2251
microsoftwindows_10_version_1507>= 10.0.10240.0 < 10.0.10240.1956710.0.10240.19567
microsoftwindows_10_version_1607>= 10.0.14393.0 < 10.0.14393.550110.0.14393.5501
microsoftwindows_10_version_1809>= 10.0.0 < 10.0.17763.365010.0.17763.3650
microsoftwindows_10_version_1809>= 10.0.17763.0 < 10.0.17763.365010.0.17763.3650
microsoftwindows_10_version_20h2>= 10.0.0 < 10.0.19042.225110.0.19042.2251
microsoftwindows_10_version_21h1>= 10.0.0 < 10.0.19043.225110.0.19043.2251
microsoftwindows_10_version_21h2>= 10.0.19043.0 < 10.0.19044.225110.0.19044.2251
microsoftwindows_10_version_22h2>= 10.0.19045.0 < 10.0.19045.225110.0.19045.2251
microsoftwindows_11_21h2< 10.0.22000.121910.0.22000.1219
microsoftwindows_11_22h2< 10.0.22621.81910.0.22621.819
microsoftwindows_11_version_21h2>= 10.0.0 < 10.0.22000.121910.0.22000.1219
microsoftwindows_11_version_22h2>= 10.0.22621.0 < 10.0.22621.81910.0.22621.819
microsoftwindows_7
microsoftwindows_7>= 6.1.0 < 6.1.7601.262216.1.7601.26221
microsoftwindows_7_service_pack_1>= 6.1.0 < 6.1.7601.262216.1.7601.26221
microsoftwindows_8.1>= 6.3.0 < 6.3.9600.206716.3.9600.20671
microsoftwindows_server_2008
microsoftwindows_server_2008_r2_service_pack_1>= 6.1.7601.0 < 6.1.7601.262216.1.7601.26221

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability resides in JScript9.dll (Chakra engine); monitor for exploitation attempts targeting this component via Internet Explorer rendering paths
  • CVE-2022-41128 is exploited in the wild; the exploit vector requires a user to access a malicious server share or website — monitor for suspicious outbound SMB/HTTP connections to unknown hosts initiated by scripting engine processes
  • APT37/ScarCruft leverages this vulnerability; the post-exploitation payload is RokRAT, which injects into explorer.exe — monitor for unusual code injection into explorer.exe
  • If Avast or Symantec AV is present, RokRAT injects into a random executable under C:\Windows\system32 instead of explorer.exe — monitor for unexpected process injection into system32 binaries
  • RokRAT achieves persistence by adding 'rubyw.exe' to Windows startup and scheduling it every four minutes — monitor for rubyw.exe in startup entries and scheduled tasks
  • RokRAT exfiltrates files with specific extensions to Yandex cloud every 30 minutes — monitor for periodic outbound connections to Yandex cloud storage from endpoints
  • The exploit delivery mechanism used malicious iframes inside Toast advertisement pop-ups rendered by Internet Explorer components — monitor for iframe-based exploitation in non-browser processes that embed IE/WebBrowser controls
  • ·CVE-2022-41128 affects the JScript9 scripting language specifically, not all Windows Scripting Languages despite the broad CVE title
  • ·The ScarCruft exploit for CVE-2022-41128 was later reused for CVE-2024-38178 with only three additional lines of code to bypass Microsoft's prior fixes — detections tuned for CVE-2022-41128 may need updating to cover the newer variant
  • ·Even after Microsoft patched this flaw, third-party software embedding outdated IE components may remain unpatched and exploitable — patch coverage cannot be assumed across all affected software

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vulncheck8.8HIGH
cisa8.8HIGH
vendor_msrc8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.