A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling application. The attacker can then install programs, view, change, or delete data, or create new accounts in the context allowed by the user’s rights. Please see the MSRC Blog Entry for important information about steps you can take to protect your system from this vulnerability.
Published: 2022-06-14
Microsoft addresses 55 CVEs in its June 2022 Patch Tuesday release, including three critical flaws.
Published: 2022-05-31
Microsoft confirms remote code execution vulnerability in Microsoft Windows Support Diagnostic Tool that has been exploited in the wild since at least April.
https://www.greynoise.io/blog/unmasking-cisas-hidden-kev-ransomware-updates
https://thehackernews.com/2025/09/researchers-uncover-gpt-4-powered.html
https://www.edgescan.com/wp-content/uploads/2024/03/2023-Vulnerability-Statistics-Report.pdf
https://thehackernews.com/2025/03/top-3-ms-office-exploits-hackers-use-in.html
https://securelist.com/vulnerability-exploit-report-q2-2024/113455/
https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-207a
https://securityaffairs.com/155420/apt/apt8-exploited-outlook-0day-target-nato.html
https://www.hhs.gov/sites/default/files/lokibot-malware-analyst-note-tlpclear.pdf
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-215a
https://thehackernews.com/2023/03/from-ransomware-to-cyber-espionage-55.html
https://www.mandiant.com/resources/blog/zero-days-exploited-2022
https://www.tenable.com/cyber-exposure/tenable-2022-threat-landscape-report
https://www.tenable.com/blog/frequently-asked-questions-about-iranian-cyber-operations
https://www.tenable.com/blog/from-bugs-to-breaches-25-significant-cves-as-mitre-cve-turns-25
https://www.tenable.com/blog/aa23-215a-2022s-top-routinely-exploited-vulnerabilities
https://www.tenable.com/blog/microsofts-august-2022-patch-tuesday-addresses-118-cves-cve-2022-34713
https://www.tenable.com/blog/microsofts-june-2022-patch-tuesday-addresses-55-cves-cve-2022-30190
https://www.tenable.com/blog/cve-2022-30190-zero-click-zero-day-in-msdt-exploited-in-the-wild
https://github.com/zavikhttak/follina-msdt-threat-investigation
https://github.com/zavikhttak/Follina-CVE-2022-30190-Analysis
https://github.com/LacunaAporia/cve-correlation-engine
https://github.com/czabatta/THM-Tempest
https://github.com/shreyash-dhawale/cve-advisory-publisher
https://github.com/Adam-KD/ioc-extractor
https://github.com/888irdy/vuln-analysis
https://github.com/krish-achanta/vuln-validator
https://github.com/u1tr0nex/CVE-2022-30190-Follina-Lab
https://github.com/Dhananjayasj/CVE-2022-30190-Follina-
https://github.com/arunpushkar-dev/VulnPriority
https://github.com/Ahmed-Arafat-Mostafa/CyberGuard-Vulnerability-Scanner
https://github.com/yashmoar11/RAG-poison
https://github.com/InnerFireZ/air-bt
https://github.com/ManglamX/CVE_ReRanker
https://github.com/ImVihanga03/Static-Malware-Analysis-Follina-CVE-2022-30190
https://github.com/TamasCzaban/vuln-prioritization-scorer
https://github.com/bcarrulo/Lab-CVE-2022-30190
https://github.com/Gorstak-Zadar/Patcher
https://github.com/dionissh/CVE-2024-21413
https://github.com/imankasthuri/follina-rce-cve-2022-30190
https://github.com/nimesh895/Malware-Analysis-Follina-CVE-2022-30190
https://github.com/mishra0230/CVE-2022-30190-Follina
https://github.com/Syedomershah99/CVE-semantic-IEEE
https://github.com/Arkha-Corvus/LetsDefend-SOC173-Follina-0-Day-Detected
https://github.com/b4nxzz/CVEs
https://github.com/RathoreAbhiii/Folina-Vulnerability-Exploitation-Detection-and-Mitigation
https://github.com/yeep1115/ICT287_CVE-2022-30190_Exploit
https://github.com/MojithaR/CVE-Vulnerability-Research
https://github.com/ethicalblue/Follina-CVE-2022-30190-Sample
https://github.com/Jump-Wang-111/AmzWord
https://github.com/ywChen-NTUST/CVE-POC
https://github.com/aminetitrofine/CVE-2022-30190
https://github.com/meowhua15/CVE-2022-30190
https://github.com/ToxicEnvelope/FOLLINA-CVE-2022-30190
https://github.com/j00sean/CVE-2022-44666
https://github.com/Zeyad-Azima/Remedy4me
https://github.com/3barz/Follina_Vagrant
https://github.com/melting0256/Enterprise-Cybersecurity
https://github.com/KJOONHWAN/CVE-Exploit-Demonstration
https://github.com/0xStarFord/FollinaXploit
https://github.com/0xAbbarhSF/FollinaXploit
https://github.com/mattjmillner/CVE-Smackdown
https://github.com/ransomsec/cvePuller
https://github.com/EkamSinghWalia/Follina-MSDT-Vulnerability-CVE-2022-30190-
https://github.com/Gra3s/CVE-2022-30190_PowerPoint
https://github.com/Gra3s/CVE-2022-30190_EXP_PowerPoint
https://github.com/Gra3s/CVE-2022-30190-Follina-PowerPoint-Version
https://github.com/MalwareTech/FollinaExtractor
https://github.com/nanaao/PicusSecurity4.Week.Repo
https://github.com/SonicWave21/Follina-CVE-2022-30190-Unofficial-patch
https://github.com/SrCroqueta/CVE-2022-30190_Temporary_Fix_Source_Code
https://github.com/SrCroqueta/CVE-2022-30190_Temporary_Fix
https://github.com/Abdibimantara/CVE-2022-30190-Analysis-With-LetsDefends-Lab
https://github.com/safakTamsesCS/PicusSecurity4.Week.Repo
https://github.com/safak-tamses/PicusSecurity4.Week.Repo
https://github.com/k508/CVE-2022-30190
https://github.com/b401/Clickstudio-compromised-certificate
https://github.com/dsibilio/follina-spring
https://github.com/abhirules27/Follina
https://github.com/joshuavanderpoll/CVE-2022-30190
https://github.com/Rojacur/FollinaPatcherCLI
https://github.com/IamVSM/msdt-follina
https://github.com/droidrzrlover/CVE-2022-30190
https://github.com/AchocolatechipPancake/MS-MSDT-Office-RCE-Follina
https://github.com/castlesmadeofsand/ms-msdt-vulnerability-pdq-package
https://github.com/suegdu/CVE-2022-30190-Follina-Patch
https://github.com/komomon/CVE-2022-30190-follina-Office-MSDT-Fixed
https://github.com/derco0n/mitigate-folina
https://github.com/ErrorNoInternet/FollinaScanner
https://github.com/gamingwithevets/msdt-disable
https://github.com/sudoaza/CVE-2022-30190
https://github.com/Cosmo121/Follina-Remediation
https://github.com/rouben/CVE-2022-30190-NSIS
https://github.com/SystemJargon/infosec_1
https://github.com/PaddlingCode/cve-2022-30190
https://github.com/kdk2933/msdt-follina-office
https://github.com/kdk2933/msdt-CVE-2022-30190
https://github.com/DOV3Y/CVE-2022-30190-ASR-Senintel-Process-Pickup
https://github.com/doocop/CVE-2022-30190
https://github.com/bytecaps/CVE-2022-30190
https://github.com/ByteCaps/CVE-2022-30190
https://github.com/zkl21hoang/msdt-follina-office-rce
https://github.com/JMousqueton/PoC-CVE-2022-30190
https://github.com/flux10n/CVE-2022-30190
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-30190
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-30190
Published: 2022-06-01
Updated: 2026-08-06
Named Vulnerability: FollinaKnown Exploited Vulnerability (KEV)
Base Score: 9.3
Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C
Severity: High
Base Score: 7.8
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity: High
EPSS: 0.99234