logo

Coverage Advisory for CVE-2022-30190

ID: dad0dc75-e74d-58e6-84b3-3476add8d582

STIX ID: report--dad0dc75-e74d-58e6-84b3-3476add8d582

Feed Name: Zscaler Security Research Blog

Threat Score
80/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This advisory describes CVE-2022-30190, a remote code execution vulnerability in Windows where malicious Word/RTF documents abuse the MS-MSDT URI scheme to execute PowerShell without needing the usual macro prompts; active malicious samples were observed and Microsoft published guidance. The document lists affected Windows versions, recommends disabling the ms-msdt URL protocol and the Windows Explorer preview pane as mitigations, and notes Zscaler detection signatures and sandbox detection for this exploit.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.