cbcvebase.
CVE-2022-30190
published 2022-06-01

CVE-2022-30190: A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully…

PriorityP188high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2022-07-05
Exploited in the wild
EPSS
99.37%
99.9th percentile
A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling application. The attacker can then install programs, view, change, or delete data, or create new accounts in the context allowed by the user’s rights. Please see the MSRC Blog Entry for important information about steps you can take to protect your system from this vulnerability.

Affected

47 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10_1507< 10.0.10240.1932510.0.10240.19325
microsoftwindows_10_1607< 10.0.14393.519210.0.14393.5192
microsoftwindows_10_1809< 10.0.17763.304610.0.17763.3046
microsoftwindows_10_20h2< 10.0.19042.176610.0.19042.1766
microsoftwindows_10_21h1< 10.0.19043.176610.0.19043.1766
microsoftwindows_10_21h2< 10.0.19044.176610.0.19044.1766
microsoftwindows_10_version_1507>= 10.0.10240.0 < 10.0.10240.1932510.0.10240.19325
microsoftwindows_10_version_1607>= 10.0.14393.0 < 10.0.14393.519210.0.14393.5192
microsoftwindows_10_version_1809>= 10.0.0 < 10.0.17763.304610.0.17763.3046
microsoftwindows_10_version_1809>= 10.0.17763.0 < 10.0.17763.304610.0.17763.3046
microsoftwindows_10_version_20h2>= 10.0.0 < 10.0.19042.176610.0.19042.1766
microsoftwindows_10_version_21h1>= 10.0.0 < 10.0.19043.176610.0.19043.1766
microsoftwindows_10_version_21h2>= 10.0.19043.0 < 10.0.19044.176610.0.19044.1766
microsoftwindows_11_21h2< 10.0.22000.73910.0.22000.739
microsoftwindows_11_version_21h2>= 10.0.0 < 10.0.22000.73910.0.22000.739
microsoftwindows_7>= 6.1.0 < 6.1.7601.259846.1.7601.25984
microsoftwindows_7_service_pack_1>= 6.1.0 < 6.1.7601.259846.1.7601.25984
microsoftwindows_8.1>= 6.3.0 < 6.3.9600.204026.3.9600.20402
microsoftwindows_server_2008
microsoftwindows_server_2008_r2_service_pack_1>= 6.1.7601.0 < 6.1.7601.259846.1.7601.25984
microsoftwindows_server_2012
microsoftwindows_server_2012>= 6.2.9200.0 < 6.2.9200.237366.2.9200.23736
microsoftwindows_server_2012_r2>= 6.3.9600.0 < 6.3.9600.204026.3.9600.20402
microsoftwindows_server_2016< 10.0.14393.519210.0.14393.5192
microsoftwindows_server_2016>= 10.0.14393.0 < 10.0.14393.519210.0.14393.5192

Detection & IOCsextracted from sources · hover to see the quote

urlms-msdt (URL protocol scheme)
pathword/_rels/document.xml.rels
hashe4973db44081591e9bff5117946defbef6041397e56164f485cf8ec57b1d8934
hash93fefc3e88ffb78abb36365fa5cf857c
yara
PDM:Exploit.Win32.Generic
yara
HEUR:Exploit.MSOffice.Agent.n
yara
HEUR:Exploit.MSOffice.Agent.gen
yara
HEUR:Exploit.MSOffice.Generic
  • RTF-format malicious documents trigger the exploit on file preview in Windows Explorer without requiring the document to be opened — monitor for MSDT spawning from explorer.exe on RTF file selection.
  • Exploitation executes PowerShell code via the ms-msdt URI scheme; detect PowerShell child processes spawned by MSDT (msdt.exe).
  • Cisco Talos released Snort rules and a ClamAV signature for CVE-2022-30190; deploy these signatures on network and endpoint sensors.
  • QAKBOT threat actor leveraged CVE-2022-30190 (Follina) as an initial access vector; correlate QAKBOT indicators with Follina exploitation activity.
  • Exploitation was observed as early as April 2022 against targets in Russia and Belarus; threat hunting should cover this timeframe in historical telemetry.
  • ·The exploit works even when macros are disabled and the document is opened in Protected Mode (for .docx); Protected View is only bypassed automatically for RTF files.
  • ·Patched versions of Office 2019 and 2021 (prior to the June 14 Patch Tuesday fix) were also vulnerable; do not assume a fully-patched pre-June-2022 Office installation is protected.

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.