← volver
CVE-2022-30190

Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability

CVSS 7.8 HIGHEPSS 99.4%● KEV
En resumen

La Herramienta de Diagnóstico de Soporte de Microsoft (MSDT) puede ser engañada para ejecutar código malicioso cuando se abre a través de un enlace en aplicaciones como Word. Un atacante puede explotar esto para tomar control de su computadora y robar datos o instalar software dañino.

Detalle técnico

Una vulnerabilidad de ejecución remota de código en MSDT activada mediante manipulación del protocolo URL desde aplicaciones como Microsoft Word permite que atacantes no autenticados ejecuten código arbitrario con los privilegios del proceso llamador. La explotación requiere interacción del usuario (apertura de un enlace o documento malicioso), pero resulta en capacidad completa de ejecución de código dentro del contexto de seguridad del usuario.

Resumen generado y traducido por IA a partir de la descripción oficial.
A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling application. The attacker can then install programs, view, change, or delete data, or create new accounts in the context allowed by the user’s rights. Please see the MSRC Blog Entry for important information about steps you can take to protect your system from this vulnerability.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
PoCs públicas encontradas94
githubgithub.com/komomon/CVE-2022-30190-follina-Office-MSDT-Fixed390githubgithub.com/JMousqueton/PoC-CVE-2022-30190157githubgithub.com/onecloudemoji/CVE-2022-30190105githubgithub.com/doocop/CVE-2022-3019060githubgithub.com/Malwareman007/Deathnote38githubgithub.com/archanchoudhury/MSDT_CVE-2022-3019038githubgithub.com/Hrishikesh7665/Follina_Exploiter_CLI33githubgithub.com/MalwareTech/FollinaExtractor31githubgithub.com/ErrorNoInternet/FollinaScanner23githubgithub.com/Noxtal/follina21githubgithub.com/0xflagplz/MS-MSDT-Office-RCE-Follina20githubgithub.com/dwisiswant0/gollina17githubgithub.com/aminetitrofine/CVE-2022-3019012githubgithub.com/drgreenthumb93/CVE-2022-30190-follina8githubgithub.com/Gra3s/CVE-2022-30190_EXP_PowerPoint8githubgithub.com/abbarhissarh/FollinaXploit8githubgithub.com/sudoaza/CVE-2022-301907githubgithub.com/ItsNee/Follina-CVE-2022-30190-POC6githubgithub.com/DerZiad/CVE-2022-301906githubgithub.com/PaddlingCode/cve-2022-301906githubgithub.com/AbdulRKB/Follina5githubgithub.com/Cosmo121/Follina-Remediation4githubgithub.com/dsibilio/follina-spring4githubgithub.com/sentinelblue/CVE-2022-301904githubgithub.com/EkamSinghWalia/Follina-MSDT-Vulnerability-CVE-2022-30190-3githubgithub.com/rouben/CVE-2022-30190-NSIS3githubgithub.com/arozx/CVE-2022-301902githubgithub.com/Zitchev/go_follina2githubgithub.com/SonicWave21/Follina-CVE-2022-30190-Unofficial-patch2githubgithub.com/amitniz/follina_cve_2022-301902githubgithub.com/jeffreybxu/five-nights-at-follina-s2githubgithub.com/gamingwithevets/msdt-disable2githubgithub.com/winstxnhdw/CVE-2022-301902githubgithub.com/SrikeshMaharaj/CVE-2022-301902githubgithub.com/gyaansastra/CVE-2022-301902githubgithub.com/swaiist/CVE-2022-30190-Fix2githubgithub.com/suenerve/CVE-2022-30190-Follina-Patch2githubgithub.com/b401/Clickstudio-compromised-certificate1githubgithub.com/rickhenderson/cve-2022-301901githubgithub.com/kdk2933/msdt-CVE-2022-301901githubgithub.com/ITMarcin2211/CVE-2022-301901githubgithub.com/derco0n/mitigate-folina1githubgithub.com/IamVSM/msdt-follina1githubgithub.com/joshuavanderpoll/CVE-2022-301901githubgithub.com/michealadams30/Cve-2022-301901githubgithub.com/melting0256/Enterprise-Cybersecurity1githubgithub.com/ToxicEnvelope/FOLLINA-CVE-2022-301901githubgithub.com/hycheng15/CVE-2022-301901githubgithub.com/Muhammad-Ali007/Follina_MSDT_CVE-2022-301901githubgithub.com/Jump-Wang-111/AmzWord1githubgithub.com/alienkeric/CVE-2022-301901githubgithub.com/ImVihanga03/Static-Malware-Analysis-Follina-CVE-2022-301901githubgithub.com/ImproveCybersecurityJaro/2022_PoC-MSDT-Follina-CVE-2022-301900githubgithub.com/rayorole/CVE-2022-301900githubgithub.com/Abdibimantara/CVE-2022-30190-Analysis-With-LetsDefends-Lab0githubgithub.com/JotaQC/CVE-2022-30190_Temporary_Fix0githubgithub.com/JotaQC/CVE-2022-30190_Temporary_Fix_Source_Code0githubgithub.com/Vaisakhkm2625/MSDT-0-Day-CVE-2022-30190-Poc0githubgithub.com/nanaao/PicusSecurity4.Week.Repo0githubgithub.com/ernestak/CVE-2022-301900githubgithub.com/ernestak/Sigma-Rule-for-CVE-2022-301900githubgithub.com/mitespsoc/CVE-2022-30190-POC0githubgithub.com/notherealhazard/follina-CVE-2022-301900githubgithub.com/Cerebrovinny/follina-CVE-2022-301900githubgithub.com/hscorpion/CVE-2022-301900githubgithub.com/aymankhder/MSDT_CVE-2022-30190-follina-0githubgithub.com/DOV3Y/CVE-2022-30190-ASR-Senintel-Process-Pickup0githubgithub.com/2867a0/CVE-2022-301900githubgithub.com/cyberdashy/CVE-2022-301900githubgithub.com/Imeneallouche/Follina-attack-CVE-2022-30190-0githubgithub.com/mattjmillner/CVE-Smackdown0githubgithub.com/bcarrulo/Lab-CVE-2022-301900githubgithub.com/Nyx2022/Follina-CVE-2022-30190-Sample0githubgithub.com/RathoreAbhiii/Folina-Vulnerability-Exploitation-Detection-and-Mitigation0githubgithub.com/seinab-ibrahim/Follina-Vulnerability-CVE-2022-30190-Exploit-Analysis0githubgithub.com/yrkuo/CVE-2022-301900githubgithub.com/Arkha-Corvus/LetsDefend-SOC173-Follina-0-Day-Detected0githubgithub.com/czabatta/THM-Tempest0githubgithub.com/nimesh895/Malware-Analysis-Follina-CVE-2022-301900githubgithub.com/shndnth/CVE-2022-301900githubgithub.com/u1tr0nex/CVE-2022-30190-Follina-Lab0githubgithub.com/shri142/ZipScan0githubgithub.com/kaleth4/CVE-2022-301900githubgithub.com/ethicalblue/Follina-CVE-2022-30190-Sample0githubgithub.com/hilt86/cve-2022-30190-mitigate0githubgithub.com/tej7gandhi/CVE-2022-30190-Zero-Click-Zero-Day-in-msdt0githubgithub.com/droidrzrlover/CVE-2022-301900githubgithub.com/Potato-9257/CVE-2022-30190_page0githubgithub.com/yeep1115/ICT287_CVE-2022-30190_Exploit0githubgithub.com/abhirules27/Follina0githubgithub.com/WesyHub/CVE-2022-30190---Follina---Poc-Exploit0githubgithub.com/castlesmadeofsand/ms-msdt-vulnerability-pdq-package0githubgithub.com/sentrium-security/Follina-Workaround-CVE-2022-301900cve_referencepacketstormsecurity.com/files/167438/Microsoft-Office-Word-MSDTJS-Code-Execution.htmlno verificado
⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →