Detecting Follina Exploits Using a Remote Answer File
ID: c232b7d0-aa08-510f-84d1-cc13ee16b554
STIX ID: report--c232b7d0-aa08-510f-84d1-cc13ee16b554
Feed Name: Binary Defense Blog
Threat Score
This report documents the Follina (CVE-2022-30190) MSDT remote code execution vulnerability actively exploited via malicious Word documents, explains a bypass technique where an MSDT "answer file" is hosted on an SMB share to avoid common command-line detections, and provides detection guidance (Sigma rule and Defender query) to locate msdt.exe executions referencing SMB-hosted answer files.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
