CVE-2022-30190
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
Description
A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling application. The attacker can then install programs, view, change, or delete data, or create new accounts in the context allowed by the user’s rights. Please see the MSRC Blog Entry for important information about steps you can take to protect your system from this vulnerability.
In plain language
AI Act nowCVE-2022-30190 is a Microsoft Windows bug that can let attackers run harmful code through the Microsoft Support Diagnostic Tool, and a typical small business on affected Windows versions should act immediately (RED).
What to do
- Update all affected Windows devices to the latest available security updates as soon as possible. 2) Ask your IT person to disable or block the MSDT URL handling behavior (per Microsoft guidance) so the attack path can’t be triggered. 3) Make sure users don’t open unexpected email attachments or office documents until patches/mitigations are in place.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2022-30190 and every CVE in our database. Create a free account — no credit card required.
Create Free Account