cbcvebase.
CVE-2022-44698
published 2022-12-13

CVE-2022-44698: Windows SmartScreen Security Feature Bypass Vulnerability

PriorityP185medium5.4CVSS 3.1
AVNACLPRNUIRSUCNILAL
KEVITWRansomware
CISA Known Exploited Vulnerabilitydue 2023-01-03
Exploited in the wild
EPSS
76.11%
99.5th percentile
Windows SmartScreen Security Feature Bypass Vulnerability

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10_1607< 10.0.14393.558210.0.14393.5582
microsoftwindows_10_1809< 10.0.17763.377010.0.17763.3770
microsoftwindows_10_20h2< 10.0.19042.236410.0.19042.2364
microsoftwindows_10_21h1< 10.0.19043.236410.0.19043.2364
microsoftwindows_10_21h2< 10.0.19044.236410.0.19044.2364
microsoftwindows_10_22h2< 10.0.19045.236410.0.19045.2364
microsoftwindows_10_version_1607>= 10.0.14393.0 < 10.0.14393.558210.0.14393.5582
microsoftwindows_10_version_1809>= 10.0.0 < 10.0.17763.377010.0.17763.3770
microsoftwindows_10_version_1809>= 10.0.17763.0 < 10.0.17763.377010.0.17763.3770
microsoftwindows_10_version_20h2>= 10.0.0 < 10.0.19042.236410.0.19042.2364
microsoftwindows_10_version_21h1>= 10.0.0 < 10.0.19043.236410.0.19043.2364
microsoftwindows_10_version_21h2>= 10.0.19044.0 < 10.0.19044.236410.0.19044.2364
microsoftwindows_10_version_22h2>= 10.0.19045.0 < 10.0.19045.236410.0.19045.2364
microsoftwindows_11_21h2< 10.0.22000.133510.0.22000.1335
microsoftwindows_11_version_21h2>= 10.0.22000.0 < 10.0.22000.133510.0.22000.1335
microsoftwindows_server_2016< 10.0.14393.558210.0.14393.5582
microsoftwindows_server_2016>= 10.0.14393.0 < 10.0.14393.558210.0.14393.5582
microsoftwindows_server_2019< 10.0.17763.377010.0.17763.3770
microsoftwindows_server_2019>= 10.0.17763.0 < 10.0.17763.377010.0.17763.3770
microsoftwindows_server_2022< 10.0.20348.136610.0.20348.1366
microsoftwindows_server_2022>= 10.0.20348.0 < 10.0.20348.136610.0.20348.1366
msrcwindows_10_version_1607
msrcwindows_10_version_1809
msrcwindows_10_version_20h2
msrcwindows_10_version_21h1

Detection & IOCsextracted from sources · hover to see the quote

  • Watch for Microsoft Office documents opened without Protected View warnings, which may indicate MOTW bypass via CVE-2022-44698, potentially enabling execution of malicious macros.
  • CISA KEV entry confirms active exploitation; prioritize patching and monitor for MOTW evasion on affected Windows 10/11 and Server 2016–2022 systems.
  • ·Zscaler's advisory mislabels CVE-2022-44698 as a 'Windows Win32k Elevation of Privilege Vulnerability'; the correct description per NVD and CISA is a Windows SmartScreen Security Feature Bypass Vulnerability. Detections should be scoped to SmartScreen/MOTW bypass, not Win32k EoP.

CVSS provenance

nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
vulncheck5.4MEDIUM
cisa5.4MEDIUM
vendor_msrc5.4MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.