Microsoft Support Diagnostic Tool 0-Day Vulnerability Being Actively Exploited
ID: a793f4c4-5a7b-5612-927d-000fbe5510a6
STIX ID: report--a793f4c4-5a7b-5612-927d-000fbe5510a6
Feed Name: Kudelski Security
**Summary:** The bulletin describes CVE-2022-30190, a zero-day in the Microsoft Support Diagnostic Tool (MSDT) actively abused since April 2022 to execute arbitrary PowerShell via the ms-msdt URI handler from malicious Microsoft Office documents (including RTF) without requiring macros; it documents nation-state activity, available PoCs, and recommends temporarily disabling the ms-msdt URL protocol and/or disabling scripted diagnostics as mitigations while providing hunting guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
