CVE-2022-44698
published 2022-12-13CVE-2022-44698: Windows SmartScreen Security Feature Bypass Vulnerability
PriorityP185medium5.4CVSS 3.1
AVNACLPRNUIRSUCNILAL
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2023-01-03
Exploited in the wild
EPSS
76.11%
99.5th percentile
Windows SmartScreen Security Feature Bypass Vulnerability
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1607 | < 10.0.14393.5582 | 10.0.14393.5582 |
| microsoft | windows_10_1809 | < 10.0.17763.3770 | 10.0.17763.3770 |
| microsoft | windows_10_20h2 | < 10.0.19042.2364 | 10.0.19042.2364 |
| microsoft | windows_10_21h1 | < 10.0.19043.2364 | 10.0.19043.2364 |
| microsoft | windows_10_21h2 | < 10.0.19044.2364 | 10.0.19044.2364 |
| microsoft | windows_10_22h2 | < 10.0.19045.2364 | 10.0.19045.2364 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.5582 | 10.0.14393.5582 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.3770 | 10.0.17763.3770 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.3770 | 10.0.17763.3770 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.2364 | 10.0.19042.2364 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.2364 | 10.0.19043.2364 |
| microsoft | windows_10_version_21h2 | >= 10.0.19044.0 < 10.0.19044.2364 | 10.0.19044.2364 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.2364 | 10.0.19045.2364 |
| microsoft | windows_11_21h2 | < 10.0.22000.1335 | 10.0.22000.1335 |
| microsoft | windows_11_version_21h2 | >= 10.0.22000.0 < 10.0.22000.1335 | 10.0.22000.1335 |
| microsoft | windows_server_2016 | < 10.0.14393.5582 | 10.0.14393.5582 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.5582 | 10.0.14393.5582 |
| microsoft | windows_server_2019 | < 10.0.17763.3770 | 10.0.17763.3770 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.3770 | 10.0.17763.3770 |
| microsoft | windows_server_2022 | < 10.0.20348.1366 | 10.0.20348.1366 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.1366 | 10.0.20348.1366 |
| msrc | windows_10_version_1607 | — | — |
| msrc | windows_10_version_1809 | — | — |
| msrc | windows_10_version_20h2 | — | — |
| msrc | windows_10_version_21h1 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Watch for Microsoft Office documents opened without Protected View warnings, which may indicate MOTW bypass via CVE-2022-44698, potentially enabling execution of malicious macros. ↗
- →CISA KEV entry confirms active exploitation; prioritize patching and monitor for MOTW evasion on affected Windows 10/11 and Server 2016–2022 systems. ↗
- ·Zscaler's advisory mislabels CVE-2022-44698 as a 'Windows Win32k Elevation of Privilege Vulnerability'; the correct description per NVD and CISA is a Windows SmartScreen Security Feature Bypass Vulnerability. Detections should be scoped to SmartScreen/MOTW bypass, not Win32k EoP. ↗
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
vulncheck5.4MEDIUM
cisa5.4MEDIUM
vendor_msrc5.4MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-22vx-vmhj-v8m6: Windows SmartScreen Security Feature Bypass Vulnerability
ghsa_unreviewed·2022-12-13
CVE-2022-44698 [MEDIUM] CWE-863 GHSA-22vx-vmhj-v8m6: Windows SmartScreen Security Feature Bypass Vulnerability
Windows SmartScreen Security Feature Bypass Vulnerability.
VulnCheck
Microsoft Defender SmartScreen Security Feature Bypass Vulnerability
vulncheck·2022·CVSS 5.4
CVE-2022-44698 [MEDIUM] CWE-755 Microsoft Defender SmartScreen Security Feature Bypass Vulnerability
Microsoft Defender SmartScreen Security Feature Bypass Vulnerability
Microsoft Defender SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file.
Affected: Microsoft Defender
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2022-Dec; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.securityweek.com/patch-tuesday-microsoft-plugs-windows-hole-exploited-ransomware-attacks; https://www.bleepingcomputer.com/news/security/microsoft-patches-windows-zero-day-used-to-drop-ransomware/; https://info.securin.io/hubfs/Securin%
CISA
Microsoft Defender SmartScreen Security Feature Bypass Vulnerability
cisa·2022-12-13·CVSS 5.4
CVE-2022-44698 [MEDIUM] CWE-755 Microsoft Defender SmartScreen Security Feature Bypass Vulnerability
Vulnerability: Microsoft Defender SmartScreen Security Feature Bypass Vulnerability
Affected: Microsoft Defender
Microsoft Defender SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file.
Required Action: Apply updates per vendor instructions.
Notes: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-44698; https://nvd.nist.gov/vuln/detail/CVE-2022-44698
Remediation Due Date: 2023-01-03
Microsoft
Windows SmartScreen Security Feature Bypass Vulnerability
vendor_msrc·2022-12-13·CVSS 5.4
CVE-2022-44698 [MEDIUM] Windows SmartScreen Security Feature Bypass Vulnerability
Windows SmartScreen Security Feature Bypass Vulnerability
FAQ: What is the relationship between Mark of the Web and Windows SmartScreen?
When you download a file from the internet, Windows adds the zone identifier or Mark of the Web as an NTFS stream to the file. So, when you run the file, Windows SmartScreen checks if there is a zone identifier Alternate Data Stream (ADS) attached to the file. If the ADS indicates ZoneId=3 which means that the file was downloaded from the internet, the SmartScreen does a reputation check. For more information on SmartScreen, please visit Microsoft Defender SmartScreen overview | Microsoft Learn.
FAQ: According to the CVSS metric, successful exploitation of this vulnerability could lead to some loss of integrity (I:L) and some loss of availability (A:L).
No detection rules found.
No public exploits indexed.
Tenable
Microsoft’s February 2024 Patch Tuesday Addresses 73 CVEs (CVE-2024-21351, CVE-2024-21412)
blogs_tenable·2024-02-13·CVSS 7.6
[HIGH] Microsoft’s February 2024 Patch Tuesday Addresses 73 CVEs (CVE-2024-21351, CVE-2024-21412)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Krebs
Fat Patch Tuesday, February 2024 Edition
blogs_krebs·2024-02-13·CVSS 5.4
CVE-2024-21412 [MEDIUM] Fat Patch Tuesday, February 2024 Edition
Microsoft Corp. today pushed software updates to plug more than 70 security holes in its Windows operating systems and related products, including two zero-day vulnerabilities that are already being exploited in active attacks.
Top of the heap on this Fat Patch Tuesday is CVE-2024-21412, a “security feature bypass” in the way Windows handles Internet Shortcut Files that Microsoft says is being targeted in active exploits. Redmond’s advisory for this bug says an attacker would need to convince or trick a user into opening a malicious shortcut file.
Researchers at Trend Micro have tied the ongoing exploitation of CVE-2024-21412 to an advanced persistent threat group dubbed “Water Hydra,” which they say has being using the vulnerability to execute a malicious Microsoft Installer File (.msi)
Krebs
Fat Patch Tuesday, February 2024 Edition
blogs_krebs·2024-02-13·CVSS 5.4
CVE-2024-21412 [MEDIUM] Fat Patch Tuesday, February 2024 Edition
Microsoft Corp. today pushed software updates to plug more than 70 security holes in its Windows operating systems and related products, including two zero-day vulnerabilities that are already being exploited in active attacks.
Top of the heap on this Fat Patch Tuesday is CVE-2024-21412 , a “security feature bypass” in the way Windows handles Internet Shortcut Files that Microsoft says is being targeted in active exploits. Redmond’s advisory for this bug says an attacker would need to convince or trick a user into opening a malicious shortcut file.
Researchers at Trend Micro have tied the ongoing exploitation of CVE-2024-21412 to an advanced persistent threat group dubbed “ Water Hydra ,” which they say has being using the vulnerability to execute a malicious Microsoft Installer File (.m
Tenable
Microsoft’s November 2023 Patch Tuesday Addresses 57 CVEs (CVE-2023-36025)
blogs_tenable·2023-11-14·CVSS 8.8
[HIGH] Microsoft’s November 2023 Patch Tuesday Addresses 57 CVEs (CVE-2023-36025)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Microsoft’s July 2023 Patch Tuesday Addresses 130 CVEs (CVE-2023-36884)
blogs_tenable·2023-07-11·CVSS 7.5
[HIGH] Microsoft’s July 2023 Patch Tuesday Addresses 130 CVEs (CVE-2023-36884)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Trendmicro
Magniber unter der Lupe
blogs_trendmicro·2023-02-02·CVSS 7.5
[HIGH] Magniber unter der Lupe
Ransomware
## Magniber unter der Lupe
Magniber-Ransomware nutzt verschiedene Schwachstellen aus, aber obwohl sie im Vergleich zu den neueren Ransomware-Kampagnen mit doppelter Erpressung eine einfachere Kill Chain verwendet, ist sie nicht weniger effektiv. Die Analyse zeigt, was zu tun ist.
By: Trend Micro Feb 02, 2023 Read time: ( words)
Save to Folio
Die Ransomware wurde bereits vor sechs Jahren entdeckt, dennoch verwenden Angreifer die Malware immer noch. Im Oktober 2022 gab es Berichte über Phishing-Attacken, über die Magniber-Ransomware verteilt wurde. Sie nutzten Standalone JavaScript-Dateien, die mit einem manipulierten Schlüssel digital signiert waren, und missbrauchten die Zero Day-Lücke CVE-2022-44698 , um Mark-of-the-Web (MOTW)-Sicherheitswarnungen zu umgehen. So konnten bö
Qualys
Qualys Threat Research Unit: Threat Thursdays, December 2022
blogs_qualys·2022-12-29
Qualys Threat Research Unit: Threat Thursdays, December 2022
## Table of Contents
From the Qualys Blogs
New Tools & Techniques
New Vulnerabilities
Threat Thursdays Webinar
Welcome to the fourth edition of the Qualys Threat Research Unit’s (TRU) “Threat Research Thursday”, where we collect and curate notable new tools, techniques, procedures, threat intelligence, cybersecurity news, malware attacks, and more. This also happens to be the last edition for the year. Feedback on our third edition, Qualys Threat Research Thursday , is more than welcome. We would love to hear from you!
## From the Qualys Blogs
Here is a roundup of the most interesting blogs from the Qualys Research Team over the past couple of weeks:
Dissecting the Empire C2 Framework – In this blog post, we take a quick dive into Empire, a popular open-source post-exploitation fra
Qualys
Qualys Threat Research Unit: Threat Thursdays, December 2022 | Qualys
blogs_qualys·2022-12-29
Qualys Threat Research Unit: Threat Thursdays, December 2022 | Qualys
#### Table of Contents
- From the Qualys Blogs
- New Tools & Techniques
- New Vulnerabilities
- Threat Thursdays Webinar
Welcome to the fourth edition of the Qualys Threat Research Unit’s (TRU) “Threat Research Thursday”, where we collect and curate notable new tools, techniques, procedures, threat intelligence, cybersecurity news, malware attacks, and more. This also happens to be the last edition for the year. Feedback on our third edition, Qualys Threat Research Thursday, is more than welcome. We would love to hear from you!
## From the Qualys Blogs
Here is a roundup of the most interesting blogs from the Qualys Research Team over the past couple of weeks:
- Dissecting the Empire C2 Framework – In this blog post, we take a quick dive into Empire, a popular open-source post-exploita
Tenable
Cybersecurity Snapshot: Phishing Scams, Salary Trends, Metaverse Risks, Log4J Poll
blogs_tenable·2022-12-16
Cybersecurity Snapshot: Phishing Scams, Salary Trends, Metaverse Risks, Log4J Poll
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Krebs
Microsoft Patch Tuesday, December 2022 Edition
blogs_krebs·2022-12-14·CVSS 8.5
[HIGH] Microsoft Patch Tuesday, December 2022 Edition
Microsoft has released its final monthly batch of security updates for 2022, fixing more than four dozen security holes in its various Windows operating systems and related software. The most pressing patches include a zero-day in a Windows feature that tries to flag malicious files from the Web, a critical bug in PowerShell , and a dangerous flaw in Windows 11 systems that was detailed publicly prior to this week’s Patch Tuesday.
The security updates include patches for Azure , Microsoft Edge, Office , SharePoint Server , SysInternals , and the .NET framework . Six of the update bundles earned Microsoft’s most dire “critical” rating, meaning they fix vulnerabilities that malware or malcontents can use to remotely commandeer an unpatched Windows system — with little to no interaction on t
Krebs
Microsoft Patch Tuesday, December 2022 Edition
blogs_krebs·2022-12-14·CVSS 8.5
[HIGH] Microsoft Patch Tuesday, December 2022 Edition
Microsoft has released its final monthly batch of security updates for 2022, fixing more than four dozen security holes in its various Windows operating systems and related software. The most pressing patches include a zero-day in a Windows feature that tries to flag malicious files from the Web, a critical bug in PowerShell, and a dangerous flaw in Windows 11 systems that was detailed publicly prior to this week’s Patch Tuesday.
The security updates include patches for Azure, Microsoft Edge, Office, SharePoint Server, SysInternals, and the .NET framework. Six of the update bundles earned Microsoft’s most dire “critical” rating, meaning they fix vulnerabilities that malware or malcontents can use to remotely commandeer an unpatched Windows system — with little to no interaction on the par
Qualys
The December 2022 Patch Tuesday Security Update Review | Qualys
blogs_qualys·2022-12-13·CVSS 7.8
CVE-2022-41089 [HIGH] The December 2022 Patch Tuesday Security Update Review | Qualys
#### Table of Contents
- Microsoft Patches for December 2022
- Adobe Patches for December 2022
- Notable Microsoft Vulnerabilities Patched
- Microsoft Critical Vulnerability Highlights
- CVE-2022-41089 | .NET Framework Remote Code Execution Vulnerability
- Microsoft Release Summary
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- EXECUTE Mitigation Using Qualys Custom Assessment and Remediation (CAR)
- EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
- Qualys Monthly Webinar Series
- This Month in Vulnerabilities & Patches
Welcome to the final second Tuesday of the year. As expected, Microsoft and Adobe have released their latest security updates and fixes. Take a break from your holiday preparations and join us as we re
Qualys
The December 2022 Patch Tuesday Security Update Review
blogs_qualys·2022-12-13·CVSS 7.8
CVE-2022-41089 [HIGH] The December 2022 Patch Tuesday Security Update Review
## Table of Contents
Microsoft Patches for December 2022
Adobe Patches for December 2022
Notable Microsoft Vulnerabilities Patched
Microsoft Critical Vulnerability Highlights
CVE-2022-41089 | .NET Framework Remote Code Execution Vulnerability
Microsoft Release Summary
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
EXECUTE Mitigation Using Qualys Custom Assessment and Remediation (CAR)
EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
Qualys Monthly Webinar Series
This Month in Vulnerabilities & Patches
Welcome to the final second Tuesday of the year. As expected, Microsoft and Adobe have released their latest security updates and fixes. Take a break from your holiday preparations and join us as we review the detai
Tenable
Microsoft’s December 2022 Patch Tuesday Addresses 48 CVEs (CVE-2022-44698)
blogs_tenable·2022-12-13·CVSS 5.4
[MEDIUM] Microsoft’s December 2022 Patch Tuesday Addresses 48 CVEs (CVE-2022-44698)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Zscaler
Zscaler found Windows Security Vulnerabilities | 12-13-2022
blogs_zscaler·CVSS 7.8
[HIGH] Zscaler found Windows Security Vulnerabilities | 12-13-2022
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Crowdstrike
December 2022 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] December 2022 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
arXiv
Vulnerability Management Chaining: An Integrated Framework for Efficient Cybersecurity Risk Prioritization
arxiv_fulltext·2025-07-10
Vulnerability Management Chaining: An Integrated Framework for Efficient Cybersecurity Risk Prioritization
## Abstract
As the number of Common Vulnerabilities and Exposures (CVE) continues to grow exponentially, security teams face increasingly difficult decisions about prioritization. Current approaches using Common Vulnerability Scoring System (CVSS) scores produce overwhelming volumes of high-priority vulnerabilities, while Exploit Prediction Scoring System (EPSS) and Known Exploited Vulnerabilities (KEV) catalog offer valuable but incomplete perspectives on actual exploitation risk. We present Vulnerability Management Chaining, a decision tree framework that systematically integrates these three approaches to achieve efficient vulnerability prioritization. Our framework employs a two-stage evaluation process: first applying threat-based filtering using KEV membership or EPSS threshold 0.08
2022-12-13
Published
2022-12-13
Added to CISA KEV
Exploited in the wild