Skip to content
COOEY

EXPOSURES › CVE-2022-44698

CVE-2022-44698

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-12-13 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-44698 ↗
⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwareexploited-in-wildunpatched

A bypass vulnerability in Microsoft Defender SmartScreen allowed attackers to evade Mark of the Web protections via a crafted malicious file.

An attacker could bypass the Mark of the Web (MOTW) defense in Microsoft Defender SmartScreen by using a specially crafted malicious file, allowing malware to execute despite MOTW protections. This is a critical, actively exploited vulnerability linked to ransomware campaigns, meaning DIB organizations must ensure their Defender SmartScreen is patched and consider supplemental file-execution controls. The failure is avoidable through timely patching and highlights reliance on a single vendor's security posture.

Shame score — A critical, actively exploited bypass vulnerability in a core endpoint security product linked to ransomware, demonstrating severe negligence in patching and reliance on a single vendor.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Microsoft Defender SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file.

AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized