Microsoft disclosed CVE-2022-30190 ("Follina"), a remote code execution flaw in the Windows Microsoft Support Diagnostic Tool (MSDT) that could be triggered through the ms-msdt URL protocol from applications such as Microsoft Word. A successful exploit allowed arbitrary code execution with the privileges of the calling application, enabling attackers to install programs, alter or delete data, and create accounts within the victim’s user context. Microsoft later issued security updates and a defense-in-depth fix through cumulative updates, while also advising customers on protections for older Windows versions.
Technical analysis showed attackers used malicious DOC, DOCX, and RTF files to fetch remote HTML that invoked ms-msdt and launched attacker-controlled PowerShell, with some RTF attacks requiring only the Windows preview pane to trigger. Observed exploit chains involved processes including WINWORD.EXE, msdt.exe, and sdiagnhost.exe, and were used to download follow-on payloads, steal data, and stage malware. Microsoft and independent researchers recommended disabling the MSDT URL protocol as a workaround until patching, and highlighted Defender detections, Microsoft 365 Defender alerting, YARA opportunities, and forensic artifacts such as PCW.debugreport.xml to help defenders identify exploitation attempts.

See affected versions and whether adversaries are exploiting it.
7 events from the most recent confirmed update back to the earliest known activity.
On 2022-07-12, Microsoft said a defense-in-depth variant related to CVE-2022-30190 had been found and fixed in the July cumulative updates. Microsoft urged customers to install the updates promptly, including KB5015805 for older platforms.
Microsoft released security updates to address CVE-2022-30190 on 2022-06-14. The updates fixed the MSDT vulnerability in supported Windows versions.
On 2022-05-30, Microsoft published guidance for the MSDT remote code execution vulnerability CVE-2022-30190 and recommended a workaround that disables the ms-msdt URL protocol. The guidance also noted available Defender detections and alerting to help identify exploitation attempts.
On May 27, 2022, nao_sec shared a VirusTotal link to a weaponized Microsoft Office document exploiting the previously unknown MSDT vulnerability later dubbed Follina. The exploit used template injection and the ms-msdt URI handler to enable code execution without Office macros.
Researchers said CVE-2022-30190 had been exploited in the wild as early as March 2022, including targeted attacks against entities in the Philippines, Nepal, and India. The reporting also linked TA413 to campaigns against the Tibetan community using malicious Office documents that abused the ms-msdt URI scheme.
VirusTotal researchers reported that Follina-related documents had been submitted before public disclosure, including likely proof-of-concept samples first seen in September and October 2021 and a smaller set that appeared to be used in real attacks. The findings pushed known activity for CVE-2022-30190 back to 2021, earlier than the March 2022 exploitation already documented publicly.
Researchers documented how to construct malicious RTF files for CVE-2022-30190 that can trigger through File Explorer preview-pane viewing on affected Windows systems. The analysis details modifying embedded OLE/CFBF object data, including remote-template URI and size fields, to support variable-length payload URLs without rebuilding allocation chains.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 80 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
11 references tracked. Mallory keeps watching after this page renders.
cymulate.com
Open sourcehuntress.com
Open sourcenacsa.gov.my
Open sourcenotes.netbytesec.com
Open sourcemsrc-blog.microsoft.com
Open sourcevirustotal.com
Open sourcemsrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.