logo

Rapid Response: Microsoft Office RCE - “Follina” MSDT Attack | Huntress

ID: 60d1dbbf-08bb-531c-ba01-a90f81a9857a

STIX ID: report--60d1dbbf-08bb-531c-ba01-a90f81a9857a

Feed Name: Huntress Blog

Threat Score
90/100

Date Published: 2024-06-24

Date Updated: 2026-04-28

...
...

Huntress analyzed a zero-day Microsoft Office/MSDT remote code execution vulnerability (CVE-2022-30190, “Follina”) that allows adversaries to trigger remote code via specially crafted Word/RTF files (including preview/hover) without macros, enabling execution of PowerShell-embedded commands and subsequent payloads; the report reproduces the exploit, describes required payload formatting, observed process trees and NTLM leakage risk, and provides detection guidance and mitigations (ASR rules and removing ms-msdt association).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.