Coverage Advisory for CVE-2022-30190
ID: dad0dc75-e74d-58e6-84b3-3476add8d582
STIX ID: report--dad0dc75-e74d-58e6-84b3-3476add8d582
Feed Name: Zscaler Security Research Blog
This advisory describes CVE-2022-30190, a remote code execution vulnerability in Windows where malicious Word/RTF documents abuse the MS-MSDT URI scheme to execute PowerShell without needing the usual macro prompts; active malicious samples were observed and Microsoft published guidance. The document lists affected Windows versions, recommends disabling the ms-msdt URL protocol and the Windows Explorer preview pane as mitigations, and notes Zscaler detection signatures and sandbox detection for this exploit.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
