logo

MSDT abused to achieve RCE on Microsoft Office

ID: 00de27ee-9212-5308-82c4-83aa50cc5439

STIX ID: report--00de27ee-9212-5308-82c4-83aa50cc5439

Feed Name: Sekoia.com

Threat Score
85/100

Date Published: 2022-06-01

Date Updated: 2026-07-20

...
...

This report documents active exploitation of CVE-2022-30190 (aka Follina) in which crafted DOCX and RTF files use MSHTML and the ms-msdt URI scheme to invoke msdt.exe with an IT_BrowseForFile argument that results in arbitrary PowerShell execution. The authors enumerate malicious document and loader hashes, IPs and domains, a retrieved PyInstaller loader that fetches a Cobalt Strike beacon, detection indicators (process execution pattern, YARA and Sigma rules), suggested GPO/registry mitigations, and note multiple unrelated samples observed in the wild suggesting reuse or repurposing by different actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.