All vulnerabilities
HIGHInfraexploited in the wild

CVE-2022-30190

Windows · Microsoft Windows Support Diagnostic Tool (MSDT)

Summary

A remote code execution flaw in the Microsoft Support Diagnostic Tool (MSDT) triggered when MSDT is invoked via the ms-msdt: URL protocol from a calling application such as Word. A malicious Office document, even via the preview pane or RTF without macros, loads a remote HTML payload that abuses MSDT to execute arbitrary code with the privileges of the calling application. It was actively exploited as a zero-day before patching and used to deliver malware in real-world phishing campaigns.

References

Related vulnerabilities

All Infra →