← Back to browse · API

CVE-2022-41091

Severity
MEDIUM
CVSS
5.4
EPSS
0.01986
Risk score
47.3
CISA KEV
Yes
PoC
No
Published
2022-11-08
Modified
2022-11-08
First seen
2026-08-07
Aliases
EUVD-2022-44334, GHSA-CCV7-V4MW-3WQQ
Products
Microsoft:Windows, Microsoft:Windows 10 Version 1507 10.0.10240.0 <10.0.10240.19567, Microsoft:Windows 10 Version 1607 10.0.14393.0 <10.0.14393.5501, Microsoft:Windows 10 Version 1809 10.0.0 <10.0.17763.3650, Microsoft:Windows 10 Version 1809 10.0.17763.0 <10.0.17763.3650, Microsoft:Windows 10 Version 20H2 10.0.0 <10.0.19042.2251, Microsoft:Windows 10 Version 21H1 10.0.0 <10.0.19043.2251, Microsoft:Windows 10 Version 21H2 10.0.19043.0 <10.0.19044.2251, Microsoft:Windows 10 Version 22H2 10.0.19045.0 <10.0.19045.2251, Microsoft:Windows 11 version 21H2 10.0.0 <10.0.22000.1219, Microsoft:Windows 11 version 22H2 10.0.22621.0 <10.0.22621.819, Microsoft:Windows Server 2016 (Server Core installation) 10.0.14393.0 <10.0.14393.5501, Microsoft:Windows Server 2016 10.0.14393.0 <10.0.14393.5501, Microsoft:Windows Server 2019 (Server Core installation) 10.0.17763.0 <10.0.17763.3650, Microsoft:Windows Server 2019 10.0.17763.0 <10.0.17763.3650, Microsoft:Windows Server 2022 10.0.20348.0 <10.0.20348.1249
Sources
euvd EUVD-2022-44334
cisa.gov CVE-2022-41091

Description

Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features.

References