Follina MSDT Attack: What We Know So Far
ID: e93851bf-1240-5606-b5cf-a064f8f0a572
STIX ID: report--e93851bf-1240-5606-b5cf-a064f8f0a572
Feed Name: ThreatLocker Blog
This report outlines the Follina (MSDT) vulnerability in Microsoft Word, where a crafted .docx file can reference a remote payload that invokes the MS-MSDT URL protocol to launch local executables or run PowerShell—potentially downloading and executing arbitrary code even with macros disabled. The write-up explains the attack flow (editing document.xml.rels to point to a malicious server that triggers MSDT), references demonstrations, and lists mitigations including disabling the MSDT URL protocol, enabling Defender cloud protections and sample submission, and applying application/ringfencing controls to block MSDT and PowerShell access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
