Summary
A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run code with the privileges of the calling application.
Why Planned Fix?
4/6Exploitation Details
Execute arbitrary code with the privileges of the calling application.
RCE (Remote Code Execution)Affected Software
| Product | Affected Versions |
|---|---|
| Microsoft Support Diagnostic Tool (MSDT) | all supported Windows versions |
Built-in Windows troubleshooting utility that collects diagnostic data and launches support troubleshooters through the ms-msdt URL handler.
Affected ComponentMSDT URL protocol handler used to launch troubleshooting flows from calling applications such as Microsoft Word.
MSDT URL protocol handler used to launch troubleshooting flows from calling applications such as Microsoft Word.
Affected Endpoints(2)ms-msdt:/, ms-msdt:/id PCWDiagnostic…
Disable the MSDT URL protocol by deleting HKEY_CLASSES_ROOT\ms-msdt; this blocks ms-msdt links but also disables click-to-launch Windows troubleshooters.
Disable the MSDT URL protocol by deleting HKEY_CLASSES_ROOT\ms-msdt; this blocks ms-msdt links but also disables click-to-launch Windows troubleshooters.
Not available
Install Microsoft’s June 14, 2022 Windows security updates; for Windows 8.1, Server 2012 R2, Server 2012, and Server 2008 SP2 use KB5015805, and keep later cumulative updates applied.
Install Microsoft’s June 14, 2022 Windows security updates; for Windows 8.1, Server 2012 R2, Server 2012, and Server 2008 SP2 use KB5015805, and keep later cumulative updates applied.
Probability of exploitation in the next 30 days
Worse than 100% of all CVEs
NVD Data
Description Summary
CVSS Base Score
CVSS Vector (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Affected Software (CPE) (17)
- •cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_10_20h2:*:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_10_21h1:*:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_11_21h2:*:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_8.1:-:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_rt_8.1:-:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_server_20h2:*:*:*:*:*:*:*:*
Sources
| Source | Article |
|---|---|
| microsoft.com | Guidance for CVE-2022-30190 Microsoft Support Diagnostic Tool Vulnerability |
| nvd.nist.gov | CVE-2022-30190 Detail |
| cisa.gov | Known Exploited Vulnerabilities Catalog |
| cloud.google.com | Move, Patch, Get Out the Way: 2022 Zero-Day Exploitation Continues at an Elevated Pace |
| unit42.paloaltonetworks.com | Threat Brief: CVE-2022-30190 – MSDT Code Execution Vulnerability |
| blog.qualys.com | Detect the Follina MSDT Vulnerability |
| tenable.com | CVE-2022-30190: Zero Click Zero Day in MSDT Exploited in the Wild |
| discuss.rapid7.com | CVE-2022-30190 - InsightVM |
| github.com | PoC-CVE-2022-30190 |
| gist.github.com | Intune Proactive Remediation - CVE-2022-30190 |
Priority History
Initial analysis