A free, unofficial fix has been designed for an actively exploitable zero-day in files signed with malformed signatures to bypass Mark-of-the-Web in Windows 10 and 11.
See also: Windows zero-day: JavaScript files bypass MoTW

Last weekend, it was discovered that cybercriminals were using isolated JavaScript files to install the Magniber ransomware on unsuspecting users' devices.
Microsoft the -Web note to every file downloaded from the Internet, which then causes your operating system to display security warnings when you try to open the file.
These Magniber JavaScript files were unique because, although they contained a Mark-of-a-Web, Windows did not display security warnings on launch.
Will Dormann, a senior vulnerability analyst at ANALYGENCE, analyzed the JS files and discovered that they were digitally signed with a malformed signature.
Microsoft SmartScreen is a program that flags and blocks malicious files, however, if the file has a malicious signature, Windows will allow it to run without security warnings.
Since this zero-day vulnerability is actively being used to commit ransomware, patching service 0patch decided to release an unofficial fix that can be used until Microsoft releases an official security update.
See also: Apple fixes new zero-day vulnerability in iPhones and iPads
The cause of this error, as explained by Mitja Kolsek in a post on 0patch, is the inability of Windows SmartScreen to read a file with a malicious signature. If SmartScreen cannot read the signature, Windows will allow the program to run, even though it should display an error.

Kolsek issued a warning that although the fix addresses most attack scenarios, there could be situations where it is bypassed.
0patch has created free patch packages for the following Microsoft Windows versions until Microsoft releases its own official updates:
- Windows 11 v21H2
- Windows 10 v21H2
- Windows 10 v21H1
- Windows 10 v20H2
- Windows 10 v2004
- Windows 10 v1909
- Windows 10 v1903
- Windows 10 v1809
- Windows 10 v1803
- Windows Server 2022
- Windows Server 2019
You will need to sign up for a free 0patch account and install its agent to micropatch your Windows device .
See also: A zero-day in Windows Mark of the Web gets an unofficial update
The agent only needs to be installed once and patches will be applied automatically without a system reboot – as long as there are no custom patching policies preventing this.
