logo

Microsoft Support Diagnostic Tool 0-Day Vulnerability Being Actively Exploited

ID: a793f4c4-5a7b-5612-927d-000fbe5510a6

STIX ID: report--a793f4c4-5a7b-5612-927d-000fbe5510a6

Feed Name: Kudelski Security

Threat Score
90/100

Date Published: 2022-05-31

Date Updated: 2026-07-22

...
...

**Summary:** The bulletin describes CVE-2022-30190, a zero-day in the Microsoft Support Diagnostic Tool (MSDT) actively abused since April 2022 to execute arbitrary PowerShell via the ms-msdt URI handler from malicious Microsoft Office documents (including RTF) without requiring macros; it documents nation-state activity, available PoCs, and recommends temporarily disabling the ms-msdt URL protocol and/or disabling scripted diagnostics as mitigations while providing hunting guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.