CVE detail
CVE-2022-30190
A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling application. The attacker can then install programs, view, change, or delete data, or create new accounts in the context allowed by the user’s rights. Please see the MSRC Blog Entry for important information about steps you can take to protect your system from this vulnerability.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 19.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
54 source links · newest first
Black Basta, one of the most successful ransomware groups over the past several years, had a major leak of its internal communications recently. The logs provide a glimpse into the playbook of a high-profile ransomware group and its preferred methods for gaining initial access to networks, as analysis from security researchers shows. “Key attack vectors […]
newswww.csoonline.comMar 3, 2025, 8:00 AMNATO and the European Union formally condemned cyber espionage operations carried out by the Russia-linked APT28 against European countries. NATO and the European Union condemned cyber espionage operations carried out by the Russia-linked threat actor APT28 (aka “Forest Blizzard”, “Fancybear” or “Strontium”) against European countries. This week the German Federal Government condemned in the strongest […]
newssecurityaffairs.comMay 5, 2024, 2:18 PMMicrosoft threat hunters say foreign APTs are interacting with OpenAI’s ChatGPT to automate malicious vulnerability research, target reconnaissance and malware creation tasks.
newswww.securityweek.comFeb 14, 2024, 6:25 PMNation-state groups Forest Blizzard, Emerald Sleet, Crimson Sandstorm, Charcoal Typhoon, and Salmon Typhoon are using large language models (LLMs) to improve and expand their criminal activities, according to findings from Microsoft Threat Intelligence Cyber Signals 2024, done in collaboration with Open AI. The study did not identify significant attacks employing the LLMs that Microsoft and […]
newswww.csoonline.comFeb 14, 2024, 12:14 PMRussia-linked group APT28 exploited Microsoft Outlook zero-day to target European NATO members, including a NATO Rapid Deployable Corps. Palo Alto Networks’ Unit 42 reported that the Russia-linked APT28 (aka “Forest Blizzard”, “Fancybear” or “Strontium”) group exploited the CVE-2023-23397 vulnerability in attacks aimed at European NATO members. Over the past 20 months, the group targeted at […]
newssecurityaffairs.comDec 8, 2023, 12:07 AM- Russia-linked APT28 group spotted exploiting Outlook flaw to hijack MS Exchange accountsSecurity Affairs
Microsoft warns that the Russia-linked APT28 group is actively exploiting the CVE-2023-23397 Outlook flaw to hijack Microsoft Exchange accounts. Microsoft’s Threat Intelligence is warning of Russia-linked cyber-espionage group APT28 (aka “Forest Blizzard”, “Fancybear” or “Strontium”) actively exploiting the CVE-2023-23397 Outlook flaw to hijack Microsoft Exchange accounts and steal sensitive information. The APT28 group (aka Fancy Bear, Pawn Storm, Sofacy Group, Sednit, BlueDelta, […]
newssecurityaffairs.comDec 5, 2023, 2:19 PM France National Agency for the Security of Information Systems warns that the Russia-linked APT28 group has breached several critical networks. The French National Agency for the Security of Information Systems ANSSI (Agence Nationale de la sécurité des systèmes d’information) warns that the Russia-linked APT28 group has been targeting multiple French organizations, including government entities, businesses, universities, […]
newssecurityaffairs.comOct 27, 2023, 1:34 PM- Spam is up, QR codes emerge as a significant threat vectorHelp Net Security
85% of phishing emails utilized malicious links in the content of the email, and spam emails increased by 30% from Q1 to Q2 2023, according to a VIPRE report. Information technology organizations also overtook financial institutions (9%) as the most targeted sector for phishing in Q2 as compared to VIPRE’s previous quarterly report. New macro-less malspam email campaign 58% of malicious emails utilized spoof content 67% of spam emails in Q2 originated in the US … More →
newswww.helpnetsecurity.comSep 4, 2023, 4:30 AM - Top 12 vulnerabilities routinely exploited in 2022Help Net Security
Cybersecurity agencies from member countries of the Five Eyes intelligence alliance have released a list of the top 12 vulnerabilities routinely exploited in 2022, plus 30 additional ones also “popular” with attackers. The top 12 “In 2022, malicious cyber actors exploited older software vulnerabilities more frequently than recently disclosed vulnerabilities and targeted unpatched, internet-facing systems. Proof of concept (PoC) code was publicly available for many of the software vulnerabilities or vulnerability chains likely facilitating exploitation … More →
newswww.helpnetsecurity.comAug 4, 2023, 1:17 PM Five Eyes government agencies have published a list of the software vulnerabilities that were most frequently exploited in malicious attacks in 2022.
newswww.securityweek.comAug 4, 2023, 9:08 AMCISA, the FBI, and NSA, along with Five Eyes cybersecurity agencies published a list of the 12 most exploited vulnerabilities of 2022. CISA, the NSA, and the FBI, in collaboration with cybersecurity authorities from Australia, Canada, New Zealand, and the United Kingdom, have published a list of the 12 most exploited vulnerabilities of 2022. The […]
newssecurityaffairs.comAug 4, 2023, 6:30 AM- In 2022, more than 40% of zero-day exploits used in the wild were variations of previous issuesSecurity Affairs
Google’s Threat Analysis Group Google states that more than 40% of zero-day flaws discovered in 2022 were variants of previous issues. The popular Threat Analysis Group (TAG) Maddie Stone wrote Google’s fourth annual year-in-review of zero-day flaws exploited in-the-wild [2021, 2020, 2019], it is built off of the mid-year 2022 review. In 2022, the researchers […]
newssecurityaffairs.comJul 30, 2023, 4:38 PM A recent RomCom cyber operation has been targeting NATO Summit guests and other entities supporting Ukraine.
newswww.securityweek.comJul 11, 2023, 11:10 AMThreat actors are targeting NATO and groups supporting Ukraine in a spear-phishing campaign distributing the RomCom RAT. On July 4, the BlackBerry Threat Research and Intelligence team uncovered a spear phishing campaign aimed at an organization supporting Ukraine abroad. The researchers discovered two lure documents submitted from an IP address in Hungary, both targeting upcoming NATO Summit guests who […]
newssecurityaffairs.comJul 10, 2023, 2:20 PMA new research report discusses the five most exploited vulnerabilities of 2022, and the five key risks that security teams should consider.
newswww.securityweek.comMar 29, 2023, 11:45 AMDeploying security patches as quickly as possible remains one of the best ways to prevent most security breaches, as attackers usually rely on exploits for publicly known vulnerabilities that have a patch available — the so-called n-day exploits. But mitigating the risk from vulnerabilities unknown to the affected software developers and don’t have a patch […]
newswww.csoonline.comMar 22, 2023, 7:38 PM- 2022 Zero-Day exploitation continues at a worrisome paceSecurity Affairs
Experts warn that 55 zero-day vulnerabilities were exploited in attacks carried out by ransomware and cyberespionage groups in 2022. Cybersecurity firm Mandiant reported that ransomware and cyberespionage groups exploited 55 zero-day flaws in attacks in the wild. Most of the zero-day vulnerabilities were in software from Microsoft, Google, and Apple. The figures show a decrease […]
newssecurityaffairs.comMar 21, 2023, 3:27 PM Mandiant has conducted an analysis of the zero-day vulnerabilities disclosed in 2022 and over a dozen were linked to cyberespionage groups.
newswww.securityweek.comMar 21, 2023, 1:13 PMSentinel Labs found evidence that links the Black Basta ransomware gang to the financially motivated hacking group FIN7. Security researchers at Sentinel Labs shared details about Black Basta‘s TTPs and assess it is highly likely the ransomware operation has ties with FIN7. The experts analyzed tools used by the ransomware gang in attacks, some of […]
newssecurityaffairs.comNov 3, 2022, 12:34 PMMore than 800 corporate users have been infected in a new QBot malware distribution campaign since September 28, Kaspersky warns.
newswww.securityweek.comOct 12, 2022, 12:19 PMThe latest Internet Security Report from the WatchGuard Threat Lab shows a reduction in overall malware detections from the peaks seen in the first half of 2021, along with an increase in threats for Chrome and Microsoft Office and the ongoing Emotet botnet resurgence. Office exploits on the rise “While overall malware attacks in Q2 fell off from the all-time highs seen in previous quarters, over 81% of detections came via TLS encrypted connections, continuing … More →
newswww.helpnetsecurity.comSep 29, 2022, 5:15 AMChina-linked cyberespionage group TA413 exploits employ a never-before-undetected backdoor called LOWZERO in attacks aimed at Tibetan entities. A China-linked cyberespionage group, tracked as TA413 (aka LuckyCat), is exploiting recently disclosed flaws in Sophos Firewall (CVE-2022-1040) and Microsoft Office (CVE-2022-30190) to deploy a never-before-detected backdoor called LOWZERO in attacks aimed at Tibetan entities. The TA413 APT group is known to be focused […]
newssecurityaffairs.comSep 26, 2022, 2:58 PM- Ex-members of the Conti ransomware gang target UkraineSecurity Affairs
Some members of the Conti ransomware gang were involved in financially motivated attacks targeting Ukraine from April to August 2022. Researchers from Google’s Threat Analysis Group (TAG) reported that some former members of the Conti cybercrime group were involved in five different campaigns targeting Ukraine between April and August 2022. The activities overlap with operations […]
newssecurityaffairs.comSep 8, 2022, 9:10 AM - Google Details Recent Ukraine CyberattacksSecurityWeek
Over the past five months, Google has been tracking a financially motivated threat actor known as UAC-0098, which has been conducting multiple malicious campaigns targeting various entities in Ukraine and Europe.
newswww.securityweek.comSep 7, 2022, 6:47 PM A wave of cybercriminals spreading malware families – including QakBot, IceID, Emotet, and RedLine Stealer – are shifting to shortcut (LNK) files for email malware delivery. Shortcuts are replacing Office macros – which are starting to be blocked by default in Office – as a way for attackers to get a foothold within networks by tricking users into infecting their PCs with malware. Keeping up with changes in the email threat landscape HP Wolf Security’s … More →
newswww.helpnetsecurity.comAug 11, 2022, 8:19 AM- New Woody RAT used in attacks aimed at Russian entitiesSecurity Affairs
An unknown threat actor is targeting Russian organizations with a new remote access trojan called Woody RAT. Malwarebytes researchers observed an unknown threat actor targeting Russian organizations with a new remote access trojan called Woody RAT. The attackers were delivering the malware using archive files and Microsoft Office documents exploiting the Follina Windows flaw (CVE-2022-30190). The assumption […]
newssecurityaffairs.comAug 4, 2022, 7:13 PM - MLNK Builder 4.2 released in Dark Web – malicious shortcut-based attacks are on the riseSecurity Affairs
Cybercriminals released a new MLNK Builder 4.2 tool for malicious shortcuts (LNK) generation with an improved Powershell and VBS Obfuscator Resecurity, Inc. (USA), a Los Angeles-based cybersecurity company protecting Fortune 500 worldwide, has detected an update of one of the most popular tools used by cybercriminals to generate malicious LNK files, so frequently used for […]
newssecurityaffairs.comJul 18, 2022, 7:49 PM - 11th July – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 11th July, please download our Threat Intelligence Bulletin. Top Attacks and Breaches An anonymous hacker identified as “ChinaDan” has claimed to have a stolen a database from the Shanghai National Police (SHGA) that includes sensitive data of 1 billion Chinese citizens, and offered to […]
vendorresearch.checkpoint.comJul 11, 2022, 1:13 PM - Rozena backdoor delivered by exploiting the Follina bugSecurity Affairs
Threat actors are exploiting the disclosed Follina Windows vulnerability to distribute the Rozena backdoor. Fortinet FortiGuard Labs researchers observed a phishing campaign that is leveraging the recently disclosed Follina security vulnerability (CVE-2022-30190, CVSS score 7.8) to distribute the Rozena backdoor on Windows systems. The Follina issue is a remote code execution vulnerability that resides in […]
newssecurityaffairs.comJul 9, 2022, 12:36 PM - Half of actively exploited zero-day issues in H1 2022 are variants of previous flawsSecurity Affairs
Google Project Zero states that in H1 2022 at least half of zero-day issues exploited in attacks were related to not properly fixed old flaws. Google Project Zero researcher Maddie Stone published a blog post that resumes her speech at the FIRST conference in June 2022, the presentation is titled “0-day In-the-Wild Exploitation in 2022…so […]
newssecurityaffairs.comJul 3, 2022, 1:31 PM Google Project Zero has observed a total of 18 exploited zero-day vulnerabilities in the first half of 2022, at least half of which exist because previous bugs were not properly addressed.
newswww.securityweek.comJul 1, 2022, 11:12 AM- 20th June – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 20th June, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Check Point Research has exposed an Iranian spear-phishing operation targeting high profile Israeli and US executives. As part of their operations, the attackers take over existing accounts of the executives and create […]
vendorresearch.checkpoint.comJun 20, 2022, 3:39 PM - Week in review: Microsoft fixes Follina, cybersecurity pros quitting, (IN)SECURE Magazine RSAC 2022Help Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: (IN)SECURE Magazine: RSAC 2022 special issue released Several of the most pressing topics discussed during this year’s Conference included issues surrounding privacy and surveillance, the positive and negative impacts of machine learning and artificial intelligence, the nuances of risk and policy, and cybersecurity-focused innovations across crypto and blockchain. 45% of cybersecurity pros are considering quitting the industry due to stress … More →
newswww.helpnetsecurity.comJun 19, 2022, 8:30 AM - Microsoft fixes Follina and 55 other CVEsHelp Net Security
June 2022 Patch Tuesday has been marked by Microsoft with the release of fixes for 55 new CVEs, as well as security updates that fix Follina (CVE-2022-30190), the Microsoft Windows Support Diagnostic Tool (MSDT) RCE that is being widely exploited by attackers. “The update for [CVE-2022-30190] is in the June 2022 cumulative Windows Updates. Microsoft strongly recommends that customers install the updates to be fully protected from the vulnerability. Customers whose systems are configured to … More →
newswww.helpnetsecurity.comJun 14, 2022, 6:47 PM Microsoft has fixed roughly 50 vulnerabilities with its June 2022 Patch Tuesday updates, including the actively exploited flaw known as Follina and CVE-2022-30190.
newswww.securityweek.comJun 14, 2022, 6:38 PMUkraine’s Computer Emergency Response Team (CERT) warns that the Russia-linked Sandworm APT group may exploit the Follina RCE vulnerability. Ukraine’s Computer Emergency Response Team (CERT) is warning that the Russia-linked Sandworm APT may be exploiting the recently discovered Follina RCE. The issue, tracked as CVE-2022-30190, impacts the Microsoft Windows Support Diagnostic Tool (MSDT). Nation-state actors […]
newssecurityaffairs.comJun 13, 2022, 6:30 PM- 13th June – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 13th June, please download our Threat Intelligence Bulletin. Top Attacks and Breaches The Italian municipality of Palermo has been victim of a ransomware attack that caused a large-scale service outage affecting over a million people. The attack was claimed by the Vice Society ransomware […]
vendorresearch.checkpoint.comJun 13, 2022, 1:00 PM This blog post was authored by Hossein Jazi and Roberto Santos.In a recent campaign, APT28, an advanced persistent threat actor linked…
newswww.malwarebytes.comJun 12, 2022, 5:00 PM- Week in review: Follina exploit delivers Qbot malware, Patch Tuesday forecast, RSAC 2022Help Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: RSA Conference 2022 coverage Check out our microsite for related news, photos, product releases, and more. Researchers unearth highly evasive “parasitic” Linux malware Security researchers at Intezer and BlackBerry have documented Symbiote, a wholly unique, multi-purpose piece of Linux malware that is nearly impossible to detect. Apple unveils passkeys for passwordless authentication to apps and websites At WWDC 2022, Apple … More →
newswww.helpnetsecurity.comJun 12, 2022, 8:00 AM May 2022 Patch Tuesday provided the final releases for several Windows 10 operating systems and this month we’ll see the final update for Internet Explorer 11. But don’t go on that family vacation thinking there will be less work to do when you come back with fewer products to support, we have an actively exploited vulnerability to deal with and an anticipated normal release of updates. The hot topic this month has been around CVE-2022-30190, … More →
newswww.helpnetsecurity.comJun 10, 2022, 5:25 AMSeveral malware families are being delivered using the recently disclosed Windows vulnerability identified as Follina and CVE-2022-30190, which remains without an official patch.
newswww.securityweek.comJun 9, 2022, 1:51 PMMore than a week has passed since Microsoft acknowledged the existence of the “Follina” vulnerability (CVE-2022-30190), after reports of it being exploited in the wild began to crop up here and there. Since then, other state-backed threat actors have started exploiting it, but now one of the most active Qbot (QakBot) malware affiliates has also been spotted leveraging Follina. Archive contains an IMG with a Word doc, shortcut file, and DLL. The LNK will execute … More →
newswww.helpnetsecurity.comJun 8, 2022, 10:40 AM- 6th June – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 6th June, please download our Threat Intelligence Bulletin. Top Attacks and Breaches An unaffiliated threat actor has been initialing a phishing campaign targeting government entities in Europe and the U.S, exploiting the recently disclosed Microsoft Office “Follina” vulnerability, tracked CVE-2022-30190. Check Point IPS, Threat […]
vendorresearch.checkpoint.comJun 6, 2022, 4:46 PM - Another nation-state actor exploits Microsoft Follina to attack European and US entitiesSecurity Affairs
A nation-state actor is attempting to exploit the Follina flaw in a recent wave of attacks against government entities in Europe and the U.S. An alleged nation-state actor is attempting to exploit the recently disclosed Microsoft Office Follina vulnerability in attacks aimed at government entities in Europe and the U.S. On May 31, Microsoft released […]
newssecurityaffairs.comJun 6, 2022, 12:11 PM - Week in review: Macro-less Office documents zero-day bug, FluBot takedown, growing DDoS threatsHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Zero-day bug exploited by attackers via macro-less Office documents (CVE-2022-30190) A newly numbered Windows zero-day vulnerability (CVE-2022-30190) is being exploited in the wild via specially crafted Office documents (without macros), security researchers are warning. And a variety of attackers have started leveraging it. FluBot takedown: Law enforcement takes control of Android spyware’s infrastructure An international law enforcement operation involving 11 … More →
newswww.helpnetsecurity.comJun 5, 2022, 8:00 AM - Attackers are leveraging Follina. What can you do?Help Net Security
As the world is waiting for Microsoft to push out a patch for CVE-2022-30190, aka “Follina”, attackers around the world are exploiting the vulnerability in a variety of campaigns. A complex vulnerability Microsoft has described CVE-2022-30190 as a Microsoft Windows Support Diagnostic Tool (MSDT) remote code execution vulnerability, confirmed it affects an overwheming majority of Windows and Windows Server versions, and advised on a workaround to be implemented until a patch is ready. Vulnerability analysts … More →
newswww.helpnetsecurity.comJun 3, 2022, 4:08 PM A China-linked APT group is actively exploiting the recently disclosed Follina zero-day flaw in Microsoft Office in attacks in the wild. China-linked APT group TA413 has been observed exploiting the recently disclosed Follina zero-day flaw (tracked as CVE-2022-30190 and rated CVSS score 7.8) in Microsoft Office in attacks in the wild. This week, the cybersecurity researcher nao_sec discovered a malicious Word […]
newssecurityaffairs.comJun 1, 2022, 10:25 AMThe Windows zero-day vulnerability identified as Follina and CVE-2022-30190 is being exploited in an increasing number of attacks, including by a Chinese APT group.
newswww.securityweek.comJun 1, 2022, 10:21 AMe vulnerability that exploits the ms-msdt Microsoft Office Uniform Resource Identifier (URI) scheme is now tracked with CVE-2022-30190 and has been shown to work on all versions of Microsoft Office and Windows Server, including Office 365 which was previously thought to not be vulnerable. Successful exploitation of the diagnostic and troubleshooting to
newswww.itpro.comJun 1, 2022, 10:13 AMCVE-2022-30190 enables remote code execution with the same privileges in the calling application and there are proof-of-concept examples of zero-click variants. We recommend protections and mitigations.
vendorunit42.paloaltonetworks.comMay 31, 2022, 9:45 PMAttackers are actively exploiting an unpatched remote code execution (RCE) vulnerability in a Windows component called the Microsoft Support Diagnostic Tool (MSDT) through weaponized Word documents. Microsoft has responded with mitigation advice that can be used to block the attacks until a permanent patch is released. An exploit for the vulnerability, now tracked as CVE-2022-30190, […]
newswww.csoonline.comMay 31, 2022, 7:29 PMMicrosoft released workarounds for a recently discovered zero-day vulnerability, dubbed Follina, in the Microsoft Office productivity suite. Microsoft has released workarounds for a recently discovered zero-day vulnerability, dubbed Follina and tracked as CVE-2022-30190 (CVSS score 7.8), in the Microsoft Office productivity suite. “On Monday May 30, 2022, Microsoft issued CVE-2022-30190 regarding the Microsoft Support Diagnostic Tool (MSDT) in Windows […]
newssecurityaffairs.comMay 31, 2022, 11:19 AMMicrosoft has confirmed that Windows is affected by a zero-day vulnerability after researchers warned of exploitation in the wild.
newswww.securityweek.comMay 31, 2022, 10:25 AM- Zero-day bug exploited by attackers via macro-less Office documents (CVE-2022-30190)Help Net Security
A newly numbered Windows zero-day vulnerability (CVE-2022-30190) is being exploited in the wild via specially crafted Office documents (without macros), security researchers are warning. After initially dismissing the vulnerability as “not a security related issue”, Microsoft has now issued a CVE and has offered a temporary workaround until fixes can be provided. Detected attacks Boobytrapped office files delivered via email are one of the most common tactics attackers use to compromise endpoints, and they are … More →
newswww.helpnetsecurity.comMay 31, 2022, 9:12 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2022-35747CVSS 5.9 · Medium
Windows Point-to-Point Protocol (PPP) Denial of Service Vulnerability
1 mention - CVE-2022-35743CVSS 7.8 · High
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
- CVE-2022-34713CVSS 7.8 · High
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
KEV listed10 mentions - CVE-2022-22047CVSS 7.8 · High
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
- CVE-2022-26925CVSS 8.1 · High
Windows LSA Spoofing Vulnerability
- CVE-2022-26904CVSS 7.0 · High
Windows User Profile Service Elevation of Privilege Vulnerability