CVE-2022-30190
A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling application. The attacker can then install programs, view, change, or delete data, or create new accounts in the context allowed by the user’s rights. Please see the MSRC Blog Entry for important information about steps you can take to protect your system from this vulnerability.
- Affected products
- Office, Windows 10, Windows 8.1, Windows Server 2008, Windows Server 2012, Windows Server 2016, Windows Support Diagnostic Tool, Windows
- Microsoft Windows 10 1507
- < 10.0.10240.19325
- Microsoft Windows 10 1607
- < 10.0.14393.5192
- Microsoft Windows 10 1809
- < 10.0.17763.3046
- Microsoft Windows 10 20h2
- < 10.0.19042.1766
- Microsoft Windows 10 21h1
- < 10.0.19043.1766
- Microsoft Windows 10 21h2
- < 10.0.19044.1766
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 99.2% (100th percentile)
- NVD status
- Analyzed
- Published
- 2022-06-01
CVE-2022-30190 at NVD
100 known exploits for CVE-2022-30190
Proof-of-concept code and exploit modules indexed by Sploitus
MSDT_CVE-2022-30190
CVE-2022-30190
CVE-2022-30190
CVE-2022-30190
FollinaScanner
Follina_Exploiter_CLI
follina-spring
CVE-2022-30190
Deathnote
CVE-2022-30190
CVE-2022-30190-Follina-Patch
CVE-2022-30190-Fix
CVE-2022-30190-Zero-Click-Zero-Day-in-msdt
CVE-2022-30190
Follina-MSDT-Vulnerability-CVE-2022-30190-
CVE-2022-30190_EXP_PowerPoint
FollinaXploit
CVE-2022-30190_Temporary_Fix
CVE-2022-30190_Temporary_Fix_Source_Code
FollinaExtractor
CVE-2022-30190-Follina-Lab
PoC-CVE-2022-30190
msdt-follina
2022_PoC-MSDT-Follina-CVE-2022-30190
Follina-attack-CVE-2022-30190-
CVE-2022-30190
ICT287_CVE-2022-30190_Exploit
CVE-2022-30190-follina
CVE-2022-30190-ASR-Senintel-Process-Pickup
CVE-2022-30190
CVE-2022-30190
Follina-Remediation
AmzWord
Static-Malware-Analysis-Follina-CVE-2022-30190
PoC-CVE-2022-30190
follina
Follina-CVE-2022-30190-Sample
cve-2022-30190
follina-msdt-threat-investigation
MS-MSDT-Office-RCE-Follina
Follina-CVE-2022-30190-POC
CVE-2022-30190
CVE-2022-30190-follina-Office-MSDT-Fixed
CVE-2022-30190
CVE-2022-30190
follina_cve_2022-30190
MSDT_CVE-2022-30190-follina-
Follina
FOLLINA-CVE-2022-30190
CVE-2022-30190
follina-CVE-2022-30190
ZipScan
Follina-Workaround-CVE-2022-30190
Follina-Vulnerability-CVE-2022-30190-Exploit-Analysis
cve-2022-30190
CVE-2022-30190
PicusSecurity4.Week.Repo
Follina_MSDT_CVE-2022-30190
Cve-2022-30190
CVE-2022-30190-NSIS
CVE-2022-30190-POC
CVE-2022-30190
CVE-2022-30190
Follina-CVE-2022-30190-Sample
Malware-Analysis-Follina-CVE-2022-30190
CVE-2022-30190
CVE-2022-30190
cve-2022-30190-mitigate
CVE-2022-30190---Follina---Poc-Exploit
CVE-2022-30190
CVE-2022-30190
CVE-2022-30190_page
MSDT-0-Day-CVE-2022-30190-Poc
LetsDefend-SOC173-Follina-0-Day-Detected
CVE-2022-30190
CVE-2022-30190
CVE-2022-30190
msdt-disable
Sigma-Rule-for-CVE-2022-30190
mitigate-folina
THM-Tempest
msdt-CVE-2022-30190
five-nights-at-follina-s
Follina-CVE-2022-30190-Unofficial-patch
follina-CVE-2022-30190
go_follina
Folina-Vulnerability-Exploitation-Detection-and-Mitigation
Follina
CVE-2022-30190-Analysis-With-LetsDefends-Lab
Exploit for CVE-2022-30190
Exploit for CVE-2022-30190
Exploit for CVE-2022-30190
Exploit for Improper Input Validation in Microsoft
Exploit for CVE-2022-30190
Exploit for CVE-2022-30190
Exploit for Path Traversal in Microsoft
Exploit for CVE-2022-30190
Exploit for CVE-2022-30190
Exploit for Improper Input Validation in Microsoft
Exploit for CVE-2022-30190