CVE-2022-44698 is a Windows SmartScreen Security Feature Bypass Vulnerability affecting multiple versions of Windows 10, 11, and Server. The vulnerability has a CVSS score of 5.4 (MEDIUM), indicating a low attack complexity and requiring user interaction, but it can lead to limited integrity and availability impacts. This CVE is actively exploited, notably by the Magniber ransomware, and has a high EPSS score and significant community discussion, despite no public exploit code being available on platforms like Metasploit or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.14393.5582CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:*:* | ||
< 10.0.17763.3770CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:*:* | ||
< 10.0.19042.2364CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_20h2:*:*:*:*:*:*:*:* | ||
< 10.0.19043.2364CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_21h1:*:*:*:*:*:*:*:* | ||
< 10.0.19044.2364CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.