Skip to main content

CVE detail

CVE-2022-30190

A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling application. The attacker can then install programs, view, change, or delete data, or create new accounts in the context allowed by the user’s rights. Please see the MSRC Blog Entry for important information about steps you can take to protect your system from this vulnerability.

CVSS 7.8 · HighBuzz score 74.0KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 74.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 19.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
30.0
54 evidence mentions in the snapshot
Diversity score
19.0
8 sources across 2 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
54 source links · newest first
  • Black Basta, one of the most successful ransomware groups over the past several years, had a major leak of its internal communications recently. The logs provide a glimpse into the playbook of a high-profile ransomware group and its preferred methods for gaining initial access to networks, as analysis from security researchers shows. “Key attack vectors […]

    newswww.csoonline.comMar 3, 2025, 8:00 AM
  • NATO and the European Union formally condemned cyber espionage operations carried out by the Russia-linked APT28 against European countries. NATO and the European Union condemned cyber espionage operations carried out by the Russia-linked threat actor APT28 (aka “Forest Blizzard”, “Fancybear” or “Strontium”) against European countries. This week the German Federal Government condemned in the strongest […]

    newssecurityaffairs.comMay 5, 2024, 2:18 PM
  • Microsoft threat hunters say foreign APTs are interacting with OpenAI’s ChatGPT to automate malicious vulnerability research, target reconnaissance and malware creation tasks.

    newswww.securityweek.comFeb 14, 2024, 6:25 PM
  • Nation-state groups Forest Blizzard, Emerald Sleet, Crimson Sandstorm, Charcoal Typhoon, and Salmon Typhoon are using large language models (LLMs) to improve and expand their criminal activities, according to findings from Microsoft Threat Intelligence Cyber Signals 2024, done in collaboration with Open AI. The study did not identify significant attacks employing the LLMs that Microsoft and […]

    newswww.csoonline.comFeb 14, 2024, 12:14 PM
  • Russia-linked group APT28 exploited Microsoft Outlook zero-day to target European NATO members, including a NATO Rapid Deployable Corps. Palo Alto Networks’ Unit 42 reported that the Russia-linked APT28 (aka “Forest Blizzard”, “Fancybear” or “Strontium”) group exploited the CVE-2023-23397 vulnerability in attacks aimed at European NATO members. Over the past 20 months, the group targeted at […]

    newssecurityaffairs.comDec 8, 2023, 12:07 AM
  • Microsoft warns that the Russia-linked APT28 group is actively exploiting the CVE-2023-23397 Outlook flaw to hijack Microsoft Exchange accounts. Microsoft’s Threat Intelligence is warning of Russia-linked cyber-espionage group APT28 (aka “Forest Blizzard”, “Fancybear” or “Strontium”) actively exploiting the CVE-2023-23397 Outlook flaw to hijack Microsoft Exchange accounts and steal sensitive information. The APT28 group (aka Fancy Bear, Pawn Storm, Sofacy Group, Sednit, BlueDelta, […]

    newssecurityaffairs.comDec 5, 2023, 2:19 PM
  • France National Agency for the Security of Information Systems warns that the Russia-linked APT28 group has breached several critical networks. The French National Agency for the Security of Information Systems ANSSI (Agence Nationale de la sécurité des systèmes d’information) warns that the Russia-linked APT28 group has been targeting multiple French organizations, including government entities, businesses, universities, […]

    newssecurityaffairs.comOct 27, 2023, 1:34 PM
  • 85% of phishing emails utilized malicious links in the content of the email, and spam emails increased by 30% from Q1 to Q2 2023, according to a VIPRE report. Information technology organizations also overtook financial institutions (9%) as the most targeted sector for phishing in Q2 as compared to VIPRE’s previous quarterly report. New macro-less malspam email campaign 58% of malicious emails utilized spoof content 67% of spam emails in Q2 originated in the US … More →

    newswww.helpnetsecurity.comSep 4, 2023, 4:30 AM
  • Top 12 vulnerabilities routinely exploited in 2022Help Net Security

    Cybersecurity agencies from member countries of the Five Eyes intelligence alliance have released a list of the top 12 vulnerabilities routinely exploited in 2022, plus 30 additional ones also “popular” with attackers. The top 12 “In 2022, malicious cyber actors exploited older software vulnerabilities more frequently than recently disclosed vulnerabilities and targeted unpatched, internet-facing systems. Proof of concept (PoC) code was publicly available for many of the software vulnerabilities or vulnerability chains likely facilitating exploitation … More →

    newswww.helpnetsecurity.comAug 4, 2023, 1:17 PM
  • Five Eyes government agencies have published a list of the software vulnerabilities that were most frequently exploited in malicious attacks in 2022.

    newswww.securityweek.comAug 4, 2023, 9:08 AM
  • CISA, the FBI, and NSA, along with Five Eyes cybersecurity agencies published a list of the 12 most exploited vulnerabilities of 2022. CISA, the NSA, and the FBI, in collaboration with cybersecurity authorities from Australia, Canada, New Zealand, and the United Kingdom, have published a list of the 12 most exploited vulnerabilities of 2022. The […]

    newssecurityaffairs.comAug 4, 2023, 6:30 AM
  • Google’s Threat Analysis Group Google states that more than 40% of zero-day flaws discovered in 2022 were variants of previous issues. The popular Threat Analysis Group (TAG) Maddie Stone wrote Google’s fourth annual year-in-review of zero-day flaws exploited in-the-wild [2021, 2020, 2019], it is built off of the mid-year 2022 review. In 2022, the researchers […]

    newssecurityaffairs.comJul 30, 2023, 4:38 PM
  • A recent RomCom cyber operation has been targeting NATO Summit guests and other entities supporting Ukraine.

    newswww.securityweek.comJul 11, 2023, 11:10 AM
  • Threat actors are targeting NATO and groups supporting Ukraine in a spear-phishing campaign distributing the RomCom RAT. On July 4, the BlackBerry Threat Research and Intelligence team uncovered a spear phishing campaign aimed at an organization supporting Ukraine abroad. The researchers discovered two lure documents submitted from an IP address in Hungary, both targeting upcoming NATO Summit guests who […]

    newssecurityaffairs.comJul 10, 2023, 2:20 PM
  • A new research report discusses the five most exploited vulnerabilities of 2022, and the five key risks that security teams should consider.

    newswww.securityweek.comMar 29, 2023, 11:45 AM
  • Deploying security patches as quickly as possible remains one of the best ways to prevent most security breaches, as attackers usually rely on exploits for publicly known vulnerabilities that have a patch available — the so-called n-day exploits. But mitigating the risk from vulnerabilities unknown to the affected software developers and don’t have a patch […]

    newswww.csoonline.comMar 22, 2023, 7:38 PM
  • Experts warn that 55 zero-day vulnerabilities were exploited in attacks carried out by ransomware and cyberespionage groups in 2022. Cybersecurity firm Mandiant reported that ransomware and cyberespionage groups exploited 55 zero-day flaws in attacks in the wild. Most of the zero-day vulnerabilities were in software from Microsoft, Google, and Apple. The figures show a decrease […]

    newssecurityaffairs.comMar 21, 2023, 3:27 PM
  • Mandiant has conducted an analysis of the zero-day vulnerabilities disclosed in 2022 and over a dozen were linked to cyberespionage groups.

    newswww.securityweek.comMar 21, 2023, 1:13 PM
  • Sentinel Labs found evidence that links the Black Basta ransomware gang to the financially motivated hacking group FIN7. Security researchers at Sentinel Labs shared details about Black Basta‘s TTPs and assess it is highly likely the ransomware operation has ties with FIN7. The experts analyzed tools used by the ransomware gang in attacks, some of […]

    newssecurityaffairs.comNov 3, 2022, 12:34 PM
  • More than 800 corporate users have been infected in a new QBot malware distribution campaign since September 28, Kaspersky warns.

    newswww.securityweek.comOct 12, 2022, 12:19 PM
  • The latest Internet Security Report from the WatchGuard Threat Lab shows a reduction in overall malware detections from the peaks seen in the first half of 2021, along with an increase in threats for Chrome and Microsoft Office and the ongoing Emotet botnet resurgence. Office exploits on the rise “While overall malware attacks in Q2 fell off from the all-time highs seen in previous quarters, over 81% of detections came via TLS encrypted connections, continuing … More →

    newswww.helpnetsecurity.comSep 29, 2022, 5:15 AM
  • China-linked cyberespionage group TA413 exploits employ a never-before-undetected backdoor called LOWZERO in attacks aimed at Tibetan entities. A China-linked cyberespionage group, tracked as TA413 (aka LuckyCat), is exploiting recently disclosed flaws in Sophos Firewall (CVE-2022-1040) and Microsoft Office (CVE-2022-30190) to deploy a never-before-detected backdoor called LOWZERO in attacks aimed at Tibetan entities. The TA413 APT group is known to be focused […]

    newssecurityaffairs.comSep 26, 2022, 2:58 PM
  • Some members of the Conti ransomware gang were involved in financially motivated attacks targeting Ukraine from April to August 2022. Researchers from Google’s Threat Analysis Group (TAG) reported that some former members of the Conti cybercrime group were involved in five different campaigns targeting Ukraine between April and August 2022. The activities overlap with operations […]

    newssecurityaffairs.comSep 8, 2022, 9:10 AM
  • Over the past five months, Google has been tracking a financially motivated threat actor known as UAC-0098, which has been conducting multiple malicious campaigns targeting various entities in Ukraine and Europe.

    newswww.securityweek.comSep 7, 2022, 6:47 PM
  • A wave of cybercriminals spreading malware families – including QakBot, IceID, Emotet, and RedLine Stealer – are shifting to shortcut (LNK) files for email malware delivery. Shortcuts are replacing Office macros – which are starting to be blocked by default in Office – as a way for attackers to get a foothold within networks by tricking users into infecting their PCs with malware. Keeping up with changes in the email threat landscape HP Wolf Security’s … More →

    newswww.helpnetsecurity.comAug 11, 2022, 8:19 AM
  • An unknown threat actor is targeting Russian organizations with a new remote access trojan called Woody RAT. Malwarebytes researchers observed an unknown threat actor targeting Russian organizations with a new remote access trojan called Woody RAT. The attackers were delivering the malware using archive files and Microsoft Office documents exploiting the Follina Windows flaw (CVE-2022-30190). The assumption […]

    newssecurityaffairs.comAug 4, 2022, 7:13 PM
  • Cybercriminals released a new MLNK Builder 4.2 tool for malicious shortcuts (LNK) generation with an improved Powershell and VBS Obfuscator Resecurity, Inc. (USA), a Los Angeles-based cybersecurity company protecting Fortune 500 worldwide, has detected an update of one of the most popular tools used by cybercriminals to generate malicious LNK files, so frequently used for […]

    newssecurityaffairs.comJul 18, 2022, 7:49 PM
  • 11th July – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 11th July, please download our Threat Intelligence Bulletin. Top Attacks and Breaches An anonymous hacker identified as “ChinaDan” has claimed to have a stolen a database from the Shanghai National Police (SHGA) that includes sensitive data of 1 billion Chinese citizens, and offered to […]

    vendorresearch.checkpoint.comJul 11, 2022, 1:13 PM
  • Threat actors are exploiting the disclosed Follina Windows vulnerability to distribute the Rozena backdoor. Fortinet FortiGuard Labs researchers observed a phishing campaign that is leveraging the recently disclosed Follina security vulnerability (CVE-2022-30190, CVSS score 7.8) to distribute the Rozena backdoor on Windows systems. The Follina issue is a remote code execution vulnerability that resides in […]

    newssecurityaffairs.comJul 9, 2022, 12:36 PM
  • Google Project Zero states that in H1 2022 at least half of zero-day issues exploited in attacks were related to not properly fixed old flaws. Google Project Zero researcher Maddie Stone published a blog post that resumes her speech at the FIRST conference in June 2022, the presentation is titled “0-day In-the-Wild Exploitation in 2022…so […]

    newssecurityaffairs.comJul 3, 2022, 1:31 PM
  • Google Project Zero has observed a total of 18 exploited zero-day vulnerabilities in the first half of 2022, at least half of which exist because previous bugs were not properly addressed.

    newswww.securityweek.comJul 1, 2022, 11:12 AM
  • 20th June – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 20th June, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Check Point Research has exposed an Iranian spear-phishing operation targeting high profile Israeli and US executives. As part of their operations, the attackers take over existing accounts of the executives and create […]

    vendorresearch.checkpoint.comJun 20, 2022, 3:39 PM
  • Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: (IN)SECURE Magazine: RSAC 2022 special issue released Several of the most pressing topics discussed during this year’s Conference included issues surrounding privacy and surveillance, the positive and negative impacts of machine learning and artificial intelligence, the nuances of risk and policy, and cybersecurity-focused innovations across crypto and blockchain. 45% of cybersecurity pros are considering quitting the industry due to stress … More →

    newswww.helpnetsecurity.comJun 19, 2022, 8:30 AM
  • Microsoft fixes Follina and 55 other CVEsHelp Net Security

    June 2022 Patch Tuesday has been marked by Microsoft with the release of fixes for 55 new CVEs, as well as security updates that fix Follina (CVE-2022-30190), the Microsoft Windows Support Diagnostic Tool (MSDT) RCE that is being widely exploited by attackers. “The update for [CVE-2022-30190] is in the June 2022 cumulative Windows Updates. Microsoft strongly recommends that customers install the updates to be fully protected from the vulnerability. Customers whose systems are configured to … More →

    newswww.helpnetsecurity.comJun 14, 2022, 6:47 PM
  • Microsoft has fixed roughly 50 vulnerabilities with its June 2022 Patch Tuesday updates, including the actively exploited flaw known as Follina and CVE-2022-30190.

    newswww.securityweek.comJun 14, 2022, 6:38 PM
  • Ukraine’s Computer Emergency Response Team (CERT) warns that the Russia-linked Sandworm APT group may exploit the Follina RCE vulnerability. Ukraine’s Computer Emergency Response Team (CERT) is warning that the Russia-linked Sandworm APT may be exploiting the recently discovered Follina RCE. The issue, tracked as CVE-2022-30190, impacts the Microsoft Windows Support Diagnostic Tool (MSDT). Nation-state actors […]

    newssecurityaffairs.comJun 13, 2022, 6:30 PM
  • 13th June – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 13th June, please download our Threat Intelligence Bulletin. Top Attacks and Breaches The Italian municipality of Palermo has been victim of a ransomware attack that caused a large-scale service outage affecting over a million people. The attack was claimed by the Vice Society ransomware […]

    vendorresearch.checkpoint.comJun 13, 2022, 1:00 PM
  • This blog post was authored by Hossein Jazi and Roberto Santos.In a recent campaign, APT28, an advanced persistent threat actor linked…

    newswww.malwarebytes.comJun 12, 2022, 5:00 PM
  • Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: RSA Conference 2022 coverage Check out our microsite for related news, photos, product releases, and more. Researchers unearth highly evasive “parasitic” Linux malware Security researchers at Intezer and BlackBerry have documented Symbiote, a wholly unique, multi-purpose piece of Linux malware that is nearly impossible to detect. Apple unveils passkeys for passwordless authentication to apps and websites At WWDC 2022, Apple … More →

    newswww.helpnetsecurity.comJun 12, 2022, 8:00 AM
  • May 2022 Patch Tuesday provided the final releases for several Windows 10 operating systems and this month we’ll see the final update for Internet Explorer 11. But don’t go on that family vacation thinking there will be less work to do when you come back with fewer products to support, we have an actively exploited vulnerability to deal with and an anticipated normal release of updates. The hot topic this month has been around CVE-2022-30190, … More →

    newswww.helpnetsecurity.comJun 10, 2022, 5:25 AM
  • Several malware families are being delivered using the recently disclosed Windows vulnerability identified as Follina and CVE-2022-30190, which remains without an official patch.

    newswww.securityweek.comJun 9, 2022, 1:51 PM
  • More than a week has passed since Microsoft acknowledged the existence of the “Follina” vulnerability (CVE-2022-30190), after reports of it being exploited in the wild began to crop up here and there. Since then, other state-backed threat actors have started exploiting it, but now one of the most active Qbot (QakBot) malware affiliates has also been spotted leveraging Follina. Archive contains an IMG with a Word doc, shortcut file, and DLL. The LNK will execute … More →

    newswww.helpnetsecurity.comJun 8, 2022, 10:40 AM
  • 6th June – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 6th June, please download our Threat Intelligence Bulletin. Top Attacks and Breaches An unaffiliated threat actor has been initialing a phishing campaign targeting government entities in Europe and the U.S, exploiting the recently disclosed Microsoft Office “Follina” vulnerability, tracked CVE-2022-30190. Check Point IPS, Threat […]

    vendorresearch.checkpoint.comJun 6, 2022, 4:46 PM
  • A nation-state actor is attempting to exploit the Follina flaw in a recent wave of attacks against government entities in Europe and the U.S. An alleged nation-state actor is attempting to exploit the recently disclosed Microsoft Office Follina vulnerability in attacks aimed at government entities in Europe and the U.S. On May 31, Microsoft released […]

    newssecurityaffairs.comJun 6, 2022, 12:11 PM
  • Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Zero-day bug exploited by attackers via macro-less Office documents (CVE-2022-30190) A newly numbered Windows zero-day vulnerability (CVE-2022-30190) is being exploited in the wild via specially crafted Office documents (without macros), security researchers are warning. And a variety of attackers have started leveraging it. FluBot takedown: Law enforcement takes control of Android spyware’s infrastructure An international law enforcement operation involving 11 … More →

    newswww.helpnetsecurity.comJun 5, 2022, 8:00 AM
  • Attackers are leveraging Follina. What can you do?Help Net Security

    As the world is waiting for Microsoft to push out a patch for CVE-2022-30190, aka “Follina”, attackers around the world are exploiting the vulnerability in a variety of campaigns. A complex vulnerability Microsoft has described CVE-2022-30190 as a Microsoft Windows Support Diagnostic Tool (MSDT) remote code execution vulnerability, confirmed it affects an overwheming majority of Windows and Windows Server versions, and advised on a workaround to be implemented until a patch is ready. Vulnerability analysts … More →

    newswww.helpnetsecurity.comJun 3, 2022, 4:08 PM
  • A China-linked APT group is actively exploiting the recently disclosed Follina zero-day flaw in Microsoft Office in attacks in the wild. China-linked APT group TA413 has been observed exploiting the recently disclosed Follina zero-day flaw (tracked as CVE-2022-30190 and rated CVSS score 7.8) in Microsoft Office in attacks in the wild. This week, the cybersecurity researcher nao_sec discovered a malicious Word […]

    newssecurityaffairs.comJun 1, 2022, 10:25 AM
  • The Windows zero-day vulnerability identified as Follina and CVE-2022-30190 is being exploited in an increasing number of attacks, including by a Chinese APT group.

    newswww.securityweek.comJun 1, 2022, 10:21 AM
  • e vulnerability that exploits the ms-msdt Microsoft Office Uniform Resource Identifier (URI) scheme is now tracked with CVE-2022-30190 and has been shown to work on all versions of Microsoft Office and Windows Server, including Office 365 which was previously thought to not be vulnerable. Successful exploitation of the diagnostic and troubleshooting to

    newswww.itpro.comJun 1, 2022, 10:13 AM
  • CVE-2022-30190 enables remote code execution with the same privileges in the calling application and there are proof-of-concept examples of zero-click variants. We recommend protections and mitigations.

    vendorunit42.paloaltonetworks.comMay 31, 2022, 9:45 PM
  • Attackers are actively exploiting an unpatched remote code execution (RCE) vulnerability in a Windows component called the Microsoft Support Diagnostic Tool (MSDT) through weaponized Word documents. Microsoft has responded with mitigation advice that can be used to block the attacks until a permanent patch is released. An exploit for the vulnerability, now tracked as CVE-2022-30190, […]

    newswww.csoonline.comMay 31, 2022, 7:29 PM
  • Microsoft released workarounds for a recently discovered zero-day vulnerability, dubbed Follina, in the Microsoft Office productivity suite. Microsoft has released workarounds for a recently discovered zero-day vulnerability, dubbed Follina and tracked as CVE-2022-30190 (CVSS score 7.8), in the Microsoft Office productivity suite. “On Monday May 30, 2022, Microsoft issued CVE-2022-30190 regarding the Microsoft Support Diagnostic Tool (MSDT) in Windows […]

    newssecurityaffairs.comMay 31, 2022, 11:19 AM
  • Microsoft has confirmed that Windows is affected by a zero-day vulnerability after researchers warned of exploitation in the wild.

    newswww.securityweek.comMay 31, 2022, 10:25 AM
  • A newly numbered Windows zero-day vulnerability (CVE-2022-30190) is being exploited in the wild via specially crafted Office documents (without macros), security researchers are warning. After initially dismissing the vulnerability as “not a security related issue”, Microsoft has now issued a CVE and has offered a temporary workaround until fixes can be provided. Detected attacks Boobytrapped office files delivered via email are one of the most common tactics attackers use to compromise endpoints, and they are … More →

    newswww.helpnetsecurity.comMay 31, 2022, 9:12 AM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence