New Zero-day Exploit spotted in the wild
ID: c2efa2b2-48c4-57d5-8c81-188173a2fed2
STIX ID: report--c2efa2b2-48c4-57d5-8c81-188173a2fed2
Feed Name: Cyble Blog
Threat Score
This report describes the CVE-2022-30190 (“Follina”) MSDT zero-day exploited via malicious Word documents that load remote HTML invoking the ms-msdt URI scheme to run PowerShell, decode and drop payloads (RAR/CAB) and execute a dropped binary; the advisory details reproduction, observed process chains, mitigation (disabling the ms-msdt protocol), and IOCs including hashes, a URL and an IP address.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
