CVE-2022-44698: Windows SmartScreen Security Feature Bypass Vulnerability
Microsoft Defender SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file.
Other sources
Windows SmartScreen Security Feature Bypass Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.5582Patch KB5021235 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.2364Patch KB5021233 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.2364Patch KB5021233 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22000.1335Patch KB5021234 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19043.2364Patch KB5021233 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19042.2364Patch KB5021233 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.1366Patch KB5021249 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.3770Patch KB5021237
Event History
Frequently Asked Questions
What is CVE-2022-44698?
CVE-2022-44698 is a security feature bypass vulnerability in Microsoft Defender SmartScreen.
What is the severity of CVE-2022-44698?
CVE-2022-44698 has a severity rating of 5.4, which is considered medium.
How does CVE-2022-44698 affect Microsoft Defender SmartScreen?
CVE-2022-44698 allows an attacker to evade Mark of the Web (MOTW) defenses in Microsoft Defender SmartScreen.
Which software products are affected by CVE-2022-44698?
Microsoft Defender, Microsoft Windows Server 2016, Microsoft Windows 11 (21H2), Microsoft Windows Server 2022, and Microsoft Windows Server 2019 are affected by CVE-2022-44698.
How can I fix CVE-2022-44698?
To fix CVE-2022-44698, apply the official patches provided by Microsoft for the affected software versions.