OS Command Injection in Microsoft Windows and Windows Server - CVE-2022-30190
Published: May 30, 2022 / Updated: November 22, 2024
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation when processing URL within the Microsoft Windows Support Diagnostic Tool (MSDT). A remote unauthenticated attacker can trick the victim to open a specially crafted file, which calls the ms-msdt tool and execute arbitrary OS commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Note, the vulnerability is being actively exploited in the wild.
UPDATED
The vulnerability resides within MSTD and not in Microsoft Word. Microsoft Word is an attack vector and not the source of vulnerability.
Affected software
Windows Server
Solutions Enabler
Unisphere 360
Unisphere for PowerMax
Unisphere for PowerMax Virtual Appliance
eVASA Provider Virtual Appliance
VASA Provider Standalone
Solutions Enabler Virtual Appliance
How to mitigate CVE-2022-30190
Solutions Enabler Virtual Appliance - update to 9.2.3.5
Unisphere 360 - update to 9.2.3.8
Unisphere for PowerMax - update to 9.2.3.20
Unisphere for PowerMax Virtual Appliance - update to 9.2.3.20
eVASA Provider Virtual Appliance - update to 9.2.4.11
VASA Provider Standalone - update to 9.2.4.21
Links to Public Exploits and PoC-codes
- Exploit #10895 - CVE-Vulnerability-Research (This repository focuses on exploring Common Vulnerabilities and Exposures (CVE), a standardized system for identifying and cataloging known cybersecurity vulnerabilities. It includes in-depth research on CVE impacts, exploitati (November 22, 2024)
- Exploit #9228 - CVE-2022-30190 (Microsoft Office Word Rce 复现(CVE-2022-30190)) (August 4, 2023)
- Exploit #9177 - CVE-2022-30190 (Follina (CVE-2022-30190) is a Microsoft Office zero-day vulnerability that has recently been discovered. It’s a high-severity vulnerability that hackers can leverage for remote code execution (RCE) attacks.) (July 10, 2023)
- Exploit #8704 - Enterprise-Cybersecurity (CVE-2022-30190(follina)) (December 29, 2022)
- Exploit #8651 - Follina-CVE-2022-30190-Sample (Educational exploit for CVE-2022-30190) (December 7, 2022)
- Exploit #8631 - msdt-follina-office-rce (CVE-2022-30190) (November 26, 2022)
- Exploit #8619 - FollinaXploit (A Command Line based python tool for exploit Zero-Day vulnerability in MSDT (Microsoft Support Diagnostic Tool) also know as 'Follina' CVE-2022-30190.) (November 20, 2022)
- Exploit #8558 - CVE-2022-30190 (A very simple MSDT "Follina" exploit **patched**) (November 1, 2022)
- Exploit #8543 - CVE-2022-30190 () (October 26, 2022)
- Exploit #8412 - CVE-2022-30190 (CVE-2022-30190 (Exploit Microsoft)) (September 28, 2022)
- Exploit #8369 - CVE-2022-30190 (A proof of concept for CVE-2022-30190 (Follina).) (September 15, 2022)
- Exploit #8217 - five-nights-at-follina-s (A Fullstack Academy Cybersecurity project examining the full cycle of the Follina (CVE-2022-30190) vulnerability, from exploit to detection and defense.) (August 5, 2022)
- Exploit #8109 - Follina-CVE-2022-30190-POC () (July 4, 2022)
- Exploit #8078 - Follina-CVE-2022-30190-PoC-sample (Educational Follina PoC Tool) (June 26, 2022)
- Exploit #8047 - CVE-2022-30190_Temporary_Fix_Source_Code (These are the source codes of the Python scripts to apply the temporary protection against the CVE-2022-30190 vulnerability (Follina)) (June 16, 2022)
- Exploit #8045 - follina-CVE-2022-30190 () (June 16, 2022)
- Exploit #8020 - follina_cve_2022-30190 (proof of concept to CVE-2022-30190 (follina)) (June 12, 2022)
- Exploit #8012 - Follina_Exploiter_CLI (Exploit Microsoft Zero-Day Vulnerability Follina (CVE-2022-30190)) (June 9, 2022)
- Exploit #8005 - follina-spring (Server to host/activate Follina payloads & generator of malicious Word documents exploiting the MS-MSDT protocol. (CVE-2022-30190)) (June 9, 2022)
- Exploit #7999 - Deathnote (Proof of Concept of CVE-2022-30190) (June 9, 2022)
- Exploit #7988 - CVE-2022-30190 (Microsoft Support Diagnostic Tool (CVE-2022-30190)) (June 8, 2022)
- Exploit #7982 - Microsoft Office Word MSDTJS (June 6, 2022)
- Exploit #7968 - msdt-follina (Microsoft MS-MSDT Follina (0-day Vulnerability) CVE-2022-30190 Attack Vector) (June 6, 2022)
- Exploit #7956 - follina (All about CVE-2022-30190, aka follina, that is a RCE vulnerability that affects Microsoft Support Diagnostic Tools (MSDT) on Office apps such as Word. This is a very simple POC, feel free to check the sources below for more threat intelligence.) (June 3, 2022)
- Exploit #7953 - CVE-2022-30190 (CVE-2022-30190 or "Follina" 0day proof of concept) (June 2, 2022)
- Exploit #7951 - CVE-2022-30190 () (June 2, 2022)
- Exploit #7949 - MS-MSDT-Office-RCE-Follina (CVE-2022-30190 | MS-MSDT Follina One Click) (June 2, 2022)
- Exploit #7948 - CVE-2022-30190---Follina---Poc-Exploit (Simple Follina poc exploit) (June 2, 2022)
- Exploit #7947 - CVE-2022-30190 () (June 2, 2022)
- Exploit #7946 - CVE-2022-30190 () (June 2, 2022)
- Exploit #7944 - CVE-2022-30190-follina-Office-MSDT-Fixed (CVE-2022-30190-follina.py-修改版,可以自定义word模板,方便实战中钓鱼使用。) (June 2, 2022)
- Exploit #7943 - CVE-2022-30190-follina (Just another PoC for the new MSDT-Exploit) (June 1, 2022)
- Exploit #7940 - MSDT-0-Day-CVE-2022-30190-Poc () (June 1, 2022)
- Exploit #7936 - gollina (Follina MS-MSDT 0-day MS Office RCE (CVE-2022-30190) PoC in Go) (June 1, 2022)
- Exploit #7934 - CVE-2022-30190-POC () (June 1, 2022)
- Exploit #7931 - CVE-2022-30190 () (May 31, 2022)
- Exploit #7929 - CVE-2022-30190 (Microsoft Office Word Rce 复现(CVE-2022-30190)) (May 31, 2022)
- Exploit #7928 - MSDT_CVE-2022-30190 (This Repository Talks about the Follina MSDT from Defender Perspective) (May 31, 2022)
- Exploit #7926 - cve-2022-30190 (Aka Follina = benign POC.) (May 31, 2022)
- Exploit #7925 - CVE-2022-30190 () (May 31, 2022)
- Exploit #7924 - PoC-CVE-2022-30190 (POC CVE-2022-30190 : CVE 0-day MS Offic RCE aka msdt follina) (May 31, 2022)
- Exploit #7923 - CVE-2022-30190 (CVE-2022-30190 Follina POC) (May 31, 2022)
External References
- https://twitter.com/nao_sec/status/1530196847679401984
- https://twitter.com/Gi7w0rm/status/1530922845253017601
- https://twitter.com/buffaloverflow/status/1530866518279565312
- https://www.virustotal.com/gui/file/4a24048f81afbe9fb62e7a6a49adbd1faf41f266b5f9feecdceb567aec096784/detection
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-30190