SB2022121336 - SmartScreen MOTW bypass in Microsoft Windows



SB2022121336 - SmartScreen MOTW bypass in Microsoft Windows

Published: December 13, 2022

Security Bulletin ID SB2022121336
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Security features bypass (CVE-ID: CVE-2022-44698)

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to an error in Windows SmartScreen. A remote attacker can bypass Mark of the Web (MOTW) defenses and potentially compromise the affected system.

Note, the vulnerability is being actively exploited in the wild.


Remediation

Install update from vendor's website.