logo

Follina MSDT Attack: What We Know So Far

ID: e93851bf-1240-5606-b5cf-a064f8f0a572

STIX ID: report--e93851bf-1240-5606-b5cf-a064f8f0a572

Feed Name: ThreatLocker Blog

Threat Score
75/100

Date Published: 2025-05-21

Date Updated: 2026-05-01

...
...

This report outlines the Follina (MSDT) vulnerability in Microsoft Word, where a crafted .docx file can reference a remote payload that invokes the MS-MSDT URL protocol to launch local executables or run PowerShell—potentially downloading and executing arbitrary code even with macros disabled. The write-up explains the attack flow (editing document.xml.rels to point to a malicious server that triggers MSDT), references demonstrations, and lists mitigations including disabling the MSDT URL protocol, enabling Defender cloud protections and sample submission, and applying application/ringfencing controls to block MSDT and PowerShell access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.