EXPOSURES › CVE-2022-41128
CVE-2022-41128
HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
⚡ RCE
⌖ EXPLOITED IN THE WILD
SHAME 72/100
rceexploited-in-wildunpatched
CVE-2022-41128: Unpatched RCE in JScript9
CVE-2022-41128, a remote code execution flaw in JScript9, was actively exploited in the wild by attackers.
Shame score — Active exploitation leading to potential unauthorized code execution.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
PLAYERS IMPLICATED
DESCRIPTION
Microsoft Windows contains an unspecified vulnerability in the JScript9 scripting language which allows for remote code execution.
AFFECTED FEDRAMP PRODUCTS · 4
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |