CVE-2022-41128
published 2022-11-09CVE-2022-41128: Windows Scripting Languages Remote Code Execution Vulnerability
PriorityP187high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-12-09
Exploited in the wild
EPSS
24.62%
97.6th percentile
Windows Scripting Languages Remote Code Execution Vulnerability
Affected
52 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1507 | < 10.0.10240.19567 | 10.0.10240.19567 |
| microsoft | windows_10_1607 | < 10.0.14393.5501 | 10.0.14393.5501 |
| microsoft | windows_10_1809 | < 10.0.17763.3650 | 10.0.17763.3650 |
| microsoft | windows_10_20h2 | < 10.0.19042.2251 | 10.0.19042.2251 |
| microsoft | windows_10_21h1 | < 10.0.19043.2251 | 10.0.19043.2251 |
| microsoft | windows_10_21h2 | < 10.0.19044.2251 | 10.0.19044.2251 |
| microsoft | windows_10_22h2 | < 10.0.19045.2251 | 10.0.19045.2251 |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.19567 | 10.0.10240.19567 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.5501 | 10.0.14393.5501 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.3650 | 10.0.17763.3650 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.3650 | 10.0.17763.3650 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.2251 | 10.0.19042.2251 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.2251 | 10.0.19043.2251 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.2251 | 10.0.19044.2251 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.2251 | 10.0.19045.2251 |
| microsoft | windows_11_21h2 | < 10.0.22000.1219 | 10.0.22000.1219 |
| microsoft | windows_11_22h2 | < 10.0.22621.819 | 10.0.22621.819 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.1219 | 10.0.22000.1219 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.819 | 10.0.22621.819 |
| microsoft | windows_7 | — | — |
| microsoft | windows_7 | >= 6.1.0 < 6.1.7601.26221 | 6.1.7601.26221 |
| microsoft | windows_7_service_pack_1 | >= 6.1.0 < 6.1.7601.26221 | 6.1.7601.26221 |
| microsoft | windows_8.1 | >= 6.3.0 < 6.3.9600.20671 | 6.3.9600.20671 |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.26221 | 6.1.7601.26221 |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability resides in JScript9.dll (Chakra engine); monitor for exploitation attempts targeting this component via Internet Explorer rendering paths ↗
- →CVE-2022-41128 is exploited in the wild; the exploit vector requires a user to access a malicious server share or website — monitor for suspicious outbound SMB/HTTP connections to unknown hosts initiated by scripting engine processes ↗
- →APT37/ScarCruft leverages this vulnerability; the post-exploitation payload is RokRAT, which injects into explorer.exe — monitor for unusual code injection into explorer.exe ↗
- →If Avast or Symantec AV is present, RokRAT injects into a random executable under C:\Windows\system32 instead of explorer.exe — monitor for unexpected process injection into system32 binaries ↗
- →RokRAT achieves persistence by adding 'rubyw.exe' to Windows startup and scheduling it every four minutes — monitor for rubyw.exe in startup entries and scheduled tasks ↗
- →RokRAT exfiltrates files with specific extensions to Yandex cloud every 30 minutes — monitor for periodic outbound connections to Yandex cloud storage from endpoints ↗
- →The exploit delivery mechanism used malicious iframes inside Toast advertisement pop-ups rendered by Internet Explorer components — monitor for iframe-based exploitation in non-browser processes that embed IE/WebBrowser controls ↗
- ·CVE-2022-41128 affects the JScript9 scripting language specifically, not all Windows Scripting Languages despite the broad CVE title ↗
- ·The ScarCruft exploit for CVE-2022-41128 was later reused for CVE-2024-38178 with only three additional lines of code to bypass Microsoft's prior fixes — detections tuned for CVE-2022-41128 may need updating to cover the newer variant ↗
- ·Even after Microsoft patched this flaw, third-party software embedding outdated IE components may remain unpatched and exploitable — patch coverage cannot be assumed across all affected software ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vulncheck8.8HIGH
cisa8.8HIGH
vendor_msrc8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-84wj-46vv-37cw: Windows Scripting Languages Remote Code Execution Vulnerability
ghsa_unreviewed·2022-11-10·CVSS 8.8
CVE-2022-41118 [HIGH] CWE-362 GHSA-84wj-46vv-37cw: Windows Scripting Languages Remote Code Execution Vulnerability
Windows Scripting Languages Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-41128.
GHSA
GHSA-778m-x5h7-mg59: Windows Scripting Languages Remote Code Execution Vulnerability
ghsa_unreviewed·2022-11-10·CVSS 7.5
CVE-2022-41128 [HIGH] CWE-787 GHSA-778m-x5h7-mg59: Windows Scripting Languages Remote Code Execution Vulnerability
Windows Scripting Languages Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-41118.
VulnCheck
Microsoft Windows Scripting Languages Remote Code Execution Vulnerability
vulncheck·2022·CVSS 8.8
CVE-2022-41128 [HIGH] CWE-787 Microsoft Windows Scripting Languages Remote Code Execution Vulnerability
Microsoft Windows Scripting Languages Remote Code Execution Vulnerability
Microsoft Windows contains an unspecified vulnerability in the JScript9 scripting language which allows for remote code execution.
Affected: Microsoft Windows
Required Action: Apply updates per vendor instructions.
Exploitation References: https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2022-Nov; https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://blog.google/threat-analysis-group/internet-explorer-0-day-exploited-by-north-korean-actor-apt37/; https://raw.githubusercontent.com/blackorbird/APT_REPORT/master/summary/2023/360_APT_Annual_Research_Report_2022.pdf; https://www.prio-n.com/a-ye
Project0
Project Zero RCA: CVE-2022-41128: Type confusion in Internet Explorer's JScript9 engine
project_zero·CVSS 8.8
CVE-2022-41128 [HIGH] Project Zero RCA: CVE-2022-41128: Type confusion in Internet Explorer's JScript9 engine
# CVE-2022-41128: Type confusion in Internet Explorer's JScript9 engine
*Benoît Sevens and Clément Lecigne, Google's Threat Analysis Group (TAG)*
## The Basics
**Disclosure Date:** 8 November 2022
**Product:** Microsoft Windows
**Advisory:**
* Security bulletin: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-41128
**Affected Versions:** Windows 7 through 11 and Windows Server 2008 through 2022, prior to the November 2022 patches
**First Patched Version:** Windows 7 through 11 and Windows Server 2008 through 2022 with November 2022 patches
**Issue/Bug Report:** N/A
**Patch CL:** N/A
**Bug-Introducing CL:** N/A
**Reporter(s):** Clément Lecigne and Benoît Sevens of Google's Threat Analysis Group
## The Code
**Proof-of-concept:**
```
function boom(m) {
var
Microsoft
Windows Scripting Languages Remote Code Execution Vulnerability
vendor_msrc·2022-11-08·CVSS 8.8
CVE-2022-41128 [HIGH] Windows Scripting Languages Remote Code Execution Vulnerability
Windows Scripting Languages Remote Code Execution Vulnerability
FAQ: The CVE title says Windows Scripting Languages, what does that mean for this vulnerability?
This vulnerability impacts the JScript9 scripting language.
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
This vulnerability requires that a user with an affected version of Windows access a malicious server. An attacker would have to host a specially crafted server share or website. An attacker would have no way to force users to visit this specially crafted server share or website, but would have to convince them to visit the server share or website, typically by way of an enticement in an email or chat message.
Windows Scripting: Windows Scripting
Microsof
CISA
Microsoft Windows Scripting Languages Remote Code Execution Vulnerability
cisa·2022-11-08·CVSS 8.8
CVE-2022-41128 [HIGH] CWE-787 Microsoft Windows Scripting Languages Remote Code Execution Vulnerability
Vulnerability: Microsoft Windows Scripting Languages Remote Code Execution Vulnerability
Affected: Microsoft Windows
Microsoft Windows contains an unspecified vulnerability in the JScript9 scripting language which allows for remote code execution.
Required Action: Apply updates per vendor instructions.
Notes: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41128; https://nvd.nist.gov/vuln/detail/CVE-2022-41128
Remediation Due Date: 2022-12-09
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Malicious ads exploited Internet Explorer zero day to drop malware
blogs_bleepingcomputer·2024-10-16·CVSS 8.8
CVE-2024-38178 [HIGH] Malicious ads exploited Internet Explorer zero day to drop malware
## Malicious ads exploited Internet Explorer zero day to drop malware
## Bill Toulas
The flaw used in zero-day attacks is tracked as CVE-2024-38178 and is a high-severity type confusion flaw in Internet Explorer.
ASEC and NCSC, responding to the campaign, informed Microsoft immediately, and the tech giant released a security update to address CVE-2024-38178 in August 2024.
Interestingly, the researchers found that ScarCruft's exploit was very similar to the one they used in the past for CVE-2022-41128, with the only addition being three lines of code designed to bypass Microsoft's previous fixes.
## From 'Toast ads' to malware
Toast notifications are pop-ups displayed in the corner of software such as antivirus or free utility programs to display notifications, alerts, or advertiseme
Checkpoint
12th December – Threat Intelligence Report
blogs_checkpoint·2022-12-12·CVSS 9.8
CVE-2021-40539 [CRITICAL] 12th December – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 12th December – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 12th December, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
The company that holds the World Cup broadcasting rights for sub-Saharan Africa has suffered a series of cyberattacks since the beginning of the tournament, targeting one of its decoding servers.
The New York-based Metropolitan Opera has been a victim of a cyberattack that shut down their website, call center and box o
Krebs
Patch Tuesday, November 2022 Election Edition
blogs_krebs·2022-11-09·CVSS 7.8
[HIGH] Patch Tuesday, November 2022 Election Edition
Let’s face it: Having “2022 election” in the headline above is probably the only reason anyone might read this story today. Still, while most of us here in the United States are anxiously awaiting the results of how well we’ve patched our Democracy, it seems fitting that Microsoft Corp. today released gobs of security patches for its ubiquitous Windows operating systems. November’s patch batch includes fixes for a whopping six zero-day security vulnerabilities that miscreants and malware are already exploiting in the wild.
Probably the scariest of the zero-day flaws is CVE-2022-41128 , a “critical” weakness in the Windows scripting languages that could be used to foist malicious software on vulnerable users who do nothing more than browse to a hacked or malicious site that exploits the we
Krebs
Patch Tuesday, November 2022 Election Edition
blogs_krebs·2022-11-09·CVSS 7.8
[HIGH] Patch Tuesday, November 2022 Election Edition
Let’s face it: Having “2022 election” in the headline above is probably the only reason anyone might read this story today. Still, while most of us here in the United States are anxiously awaiting the results of how well we’ve patched our Democracy, it seems fitting that Microsoft Corp. today released gobs of security patches for its ubiquitous Windows operating systems. November’s patch batch includes fixes for a whopping six zero-day security vulnerabilities that miscreants and malware are already exploiting in the wild.
Probably the scariest of the zero-day flaws is CVE-2022-41128, a “critical” weakness in the Windows scripting languages that could be used to foist malicious software on vulnerable users who do nothing more than browse to a hacked or malicious site that exploits the wea
Qualys
November 2022 Patch Tuesday | Microsoft Releases 65 New Vulnerabilities With 10 Critical; Adobe Releases Zero Advisories (for the First Time in Six Years).
blogs_qualys·2022-11-08·CVSS 7.5
[HIGH] November 2022 Patch Tuesday | Microsoft Releases 65 New Vulnerabilities With 10 Critical; Adobe Releases Zero Advisories (for the First Time in Six Years).
## Table of Contents
Microsoft Patch Tuesday Summary
The November 2022 Microsoft Vulnerabilities are Classified as Follows:
OpenSSL 3.x Critical Vulnerability Highlights
OpenSSL 3.x Related Blogs and Resources
Microsoft Addressed Six Zero-Day Vulnerabilities
Microsoft Patch Tuesday Critical Vulnerability Highlights
Microsoft Release Summary
Adobe Security Bulletins and Advisories
About Qualys Patch Tuesday
Qualys Threat Research Blog Posts
Qualys Threat Protection High-Rated Advisories
Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response(VMDR)
Rapid Response with Patch Management (PM)
Extend the Power of VMDR to Enterprise Mobile Devices With Qualys VMDR Mobile
Execute Mitigation UsingCustom Assessment and Remediation(CAR)
Patch Tuesday Is
Tenable
Microsoft’s November 2022 Patch Tuesday Addresses 62 CVEs (CVE-2022-41073)
blogs_tenable·2022-11-08·CVSS 7.8
[HIGH] Microsoft’s November 2022 Patch Tuesday Addresses 62 CVEs (CVE-2022-41073)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
November 2022 Patch Tuesday | Microsoft Releases 65 New Vulnerabilities With 10 Critical; Adobe Releases Zero Advisories (for the First Time in Six Years). | Qualys
blogs_qualys·2022-11-08·CVSS 7.5
[HIGH] November 2022 Patch Tuesday | Microsoft Releases 65 New Vulnerabilities With 10 Critical; Adobe Releases Zero Advisories (for the First Time in Six Years). | Qualys
#### Table of Contents
- Microsoft Patch Tuesday Summary
- The November 2022 Microsoft Vulnerabilities are Classified as Follows:
- OpenSSL 3.x Critical Vulnerability Highlights
- OpenSSL 3.x Related Blogs and Resources
- Microsoft Addressed Six Zero-Day Vulnerabilities
- Microsoft Patch Tuesday Critical Vulnerability Highlights
- Microsoft Release Summary
- Adobe Security Bulletins and Advisories
- About Qualys Patch Tuesday
- Qualys Threat Research Blog Posts
- Qualys Threat Protection High-Rated Advisories
- Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response(VMDR)
- Rapid Response with Patch Management (PM)
- Extend the Power of VMDR to Enterprise Mobile Devices With Qualys VMDR Mobile
- Execute Mitigation UsingCustom Assessment and Remediation(CAR)
Crowdstrike
November 2022 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] November 2022 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
2022-11-09
Published
2022-11-08
Added to CISA KEV
Exploited in the wild