{"cveID":"CVE-2022-41128","vendorProject":"Microsoft","product":"Windows","vulnerabilityName":"Microsoft Windows Scripting Languages Remote Code Execution Vulnerability","dateAdded":"2022-11-08","shortDescription":"Microsoft Windows contains an unspecified vulnerability in the JScript9 scripting language which allows for remote code execution.","requiredAction":"Apply updates per vendor instructions.","dueDate":"2022-12-09","knownRansomwareCampaignUse":"Unknown","notes":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41128;  https://nvd.nist.gov/vuln/detail/CVE-2022-41128","cwes":["CWE-787"],"year":2022,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2022-41128","technique":"T1566","technique_name_at_mapping":"Phishing","mapping_type":"exploitation_technique","capability_group":"code_execution","comments":"This vulnerability is exploited by a remote adversary who entices a user with an affected version of Windows to access a malicious server. The adversary hosts a specially crafted server share or website and convinces the user to visit it, typically through an email or chat message. The adversary then crafts a malicious Microsoft Office document that embeds a remote RTF template, which fetches HTML content rendered by Internet Explorer's JScript engine. This stealthy attack vector does not require Internet Explorer as the default browser. Once the victim opens the document and disables protected view, the adversary executes arbitrary code by triggering a type confusion error in the JScript engine. This allows the adversary to deliver malicious payloads, conduct reconnaissance, and exfiltrate data, while erasing traces of the exploit by clearing the browser cache and history. The impact on the victim includes unauthorized access to sensitive information and the potential installation of backdoors for further exploitation.","references":["https://blog.google/threat-analysis-group/internet-explorer-0-day-exploited-by-north-korean-actor-apt37/","https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41128"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2022-41128","technique":"T1070","technique_name_at_mapping":"Indicator Removal","mapping_type":"secondary_impact","capability_group":"code_execution","comments":"This vulnerability is exploited by a remote adversary who entices a user with an affected version of Windows to access a malicious server. The adversary hosts a specially crafted server share or website and convinces the user to visit it, typically through an email or chat message. The adversary then crafts a malicious Microsoft Office document that embeds a remote RTF template, which fetches HTML content rendered by Internet Explorer's JScript engine. This stealthy attack vector does not require Internet Explorer as the default browser. Once the victim opens the document and disables protected view, the adversary executes arbitrary code by triggering a type confusion error in the JScript engine. This allows the adversary to deliver malicious payloads, conduct reconnaissance, and exfiltrate data, while erasing traces of the exploit by clearing the browser cache and history. The impact on the victim includes unauthorized access to sensitive information and the potential installation of backdoors for further exploitation.","references":["https://blog.google/threat-analysis-group/internet-explorer-0-day-exploited-by-north-korean-actor-apt37/","https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41128"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2022-41128","technique":"T1203","technique_name_at_mapping":"Exploitation for Client Execution","mapping_type":"primary_impact","capability_group":"code_execution","comments":"This vulnerability is exploited by a remote adversary who entices a user with an affected version of Windows to access a malicious server. The adversary hosts a specially crafted server share or website and convinces the user to visit it, typically through an email or chat message. The adversary then crafts a malicious Microsoft Office document that embeds a remote RTF template, which fetches HTML content rendered by Internet Explorer's JScript engine. This stealthy attack vector does not require Internet Explorer as the default browser. Once the victim opens the document and disables protected view, the adversary executes arbitrary code by triggering a type confusion error in the JScript engine. This allows the adversary to deliver malicious payloads, conduct reconnaissance, and exfiltrate data, while erasing traces of the exploit by clearing the browser cache and history. The impact on the victim includes unauthorized access to sensitive information and the potential installation of backdoors for further exploitation.","references":["https://blog.google/threat-analysis-group/internet-explorer-0-day-exploited-by-north-korean-actor-apt37/","https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-41128"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1070","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Indicator Removal","name_at_mapping":"Indicator Removal","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":20,"has_detection_strategy":true},{"id":"T1203","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Exploitation for Client Execution","name_at_mapping":"Exploitation for Client Execution","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":35,"has_detection_strategy":true},{"id":"T1566","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Phishing","name_at_mapping":"Phishing","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":14,"has_detection_strategy":true}],"mapping_types":["exploitation_technique","primary_impact","secondary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"full","sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-23 05:47 UTC","_attack_version":"19.2"}