CISA Known Exploited Vulnerability

CVE-2022-44698 Ransomware

Microsoft · Defender

Microsoft Defender SmartScreen Security Feature Bypass Vulnerability

Date added
BOD 22-01 due date
CWE CWE-755
Ransomware Known

CISA description

Microsoft Defender SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file.

Required action

Apply updates per vendor instructions.