⚠ Actively exploited in ransomware campaigns
This vulnerability is on the CISA Known Exploited Vulnerabilities list and has been used in known ransomware attacks. CISA required action: Apply updates per vendor instructions.. Due date: 2023-01-03.
Severity
5.4MEDIUM
EPSS
67.2%
top 1.44%
CISA KEV
KEVRansomware
Added 2022-12-13
Due 2023-01-03
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedDec 13
KEV addedDec 13
KEV dueJan 3
CISA Required Action: Apply updates per vendor instructions.

Description

Windows SmartScreen Security Feature Bypass Vulnerability

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:LExploitability: 2.8 | Impact: 2.5

Affected Packages18 packages

NVDmicrosoft/windows< 10.0.14393.5582+2
NVDmicrosoft/windows_10_1607< 10.0.14393.5582
NVDmicrosoft/windows_10_1809< 10.0.17763.3770
NVDmicrosoft/windows_10_20h2< 10.0.19042.2364
NVDmicrosoft/windows_10_21h1< 10.0.19043.2364

Patches

🔴Vulnerability Details

3
GHSA
GHSA-22vx-vmhj-v8m6: Windows SmartScreen Security Feature Bypass Vulnerability2022-12-13
CVEList
Windows SmartScreen Security Feature Bypass Vulnerability2022-12-13
VulnCheck
Microsoft Defender SmartScreen Security Feature Bypass Vulnerability2022

📋Vendor Advisories

2
CISA
Microsoft Defender SmartScreen Security Feature Bypass Vulnerability2022-12-13
Microsoft
Windows SmartScreen Security Feature Bypass Vulnerability2022-12-13
CVE-2022-44698 (MEDIUM CVSS 5.4) | Windows SmartScreen Security Featur | cvebase.io