Rapid Response: Microsoft Office RCE - “Follina” MSDT Attack | Huntress
ID: 60d1dbbf-08bb-531c-ba01-a90f81a9857a
STIX ID: report--60d1dbbf-08bb-531c-ba01-a90f81a9857a
Feed Name: Huntress Blog
Huntress analyzed a zero-day Microsoft Office/MSDT remote code execution vulnerability (CVE-2022-30190, “Follina”) that allows adversaries to trigger remote code via specially crafted Word/RTF files (including preview/hover) without macros, enabling execution of PowerShell-embedded commands and subsequent payloads; the report reproduces the exploit, describes required payload formatting, observed process trees and NTLM leakage risk, and provides detection guidance and mitigations (ASR rules and removing ms-msdt association).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
