Vulnerability summary: Follina, CVE-2022-30190
ID: 31717cfe-d73e-5627-8d7b-c323abe09f2d
STIX ID: report--31717cfe-d73e-5627-8d7b-c323abe09f2d
Feed Name: Elastic Security Labs
Threat Score
On May 27, 2022 researchers disclosed "Follina" (CVE-2022-30190), an MSDT remote code execution vulnerability abused through ms-msdt URIs in Microsoft Office template injection; exploitation can occur via weaponized Office attachments and does not require macros. The report urges monitoring msdt.exe as a child of Office processes, deploying Elastic detection signatures, and references Microsoft's guidance and multiple third-party analyses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
