logo

New Zero-day Exploit spotted in the wild

ID: c2efa2b2-48c4-57d5-8c81-188173a2fed2

STIX ID: report--c2efa2b2-48c4-57d5-8c81-188173a2fed2

Feed Name: Cyble Blog

Threat Score
82/100

Date Published: 2025-05-20

Date Updated: 2026-07-16

...
...

This report describes the CVE-2022-30190 (“Follina”) MSDT zero-day exploited via malicious Word documents that load remote HTML invoking the ms-msdt URI scheme to run PowerShell, decode and drop payloads (RAR/CAB) and execute a dropped binary; the advisory details reproduction, observed process chains, mitigation (disabling the ms-msdt protocol), and IOCs including hashes, a URL and an IP address.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.