🔴🖥️👨‍💻 Windows Zero Day: MSDT Follina 👨‍💻🖥️🔴

Stimulus mind

Well-known member
  • Feb 27, 2021
    30,960
    152,909
    113

    What is Follina?​

    Follina (CVE-2022-30190) is a vulnerability in the Microsoft Support Diagnostic Tool (MSDT) that allows remote code execution on vulnerable systems through the ms-msdt protocol handler scheme. The bug is present in all supported versions of Windows.

    The vulnerability can be easily exploited by a specially crafted Word document that downloads and loads a malicious HTML file through Word’s remote template feature. The HTML file ultimately allows the attacker to load and execute PowerShell code within Windows. The vulnerability can also be exploited through the RTF file format.

    Full Article