by @jakaba
29 Nov 2023

Follina - Microsoft Office Zero-Day Exploit (CVE-2022-30190)

by @jakaba
29 Nov 2023

Follina - Microsoft Office Zero-Day Exploit (CVE-2022-30190)

CVEs

7.8 High Severity

OS

10.0.20348.2458.*
10.0.20348.2402.*
10.0.20348.2402.*
10.0.20348.2402.*
10.0.20348.2333.*
10.0.20348.770.*
10.0.20348.1903.*
10.0.20348.2700.*
10.0.20348.2700.*
10.0.20348.2700.*
10.0.17763.7009.*
18410.*
10.0.17763.6414.*
10.0.17763.6659.*
10.0.17763.5458.*
10.0.17763.3770.*
10.0.17763.5936.*
10.0.17763.5820.*
10.0.17763.6532.*
10.0.17763.5696.*
10.0.14393.7876.*
10.0.14393.7606.*
10.0.14393.7428.*
10.0.14393.6897.*
10.0.14393.5582.*
10.0.14393.6981.*
10.0.14393.6796.*
10.0.14393.7070.*
10.0.14393.7515.*
10.0.14393.7336.*
7375.*
6.2.9200.25073.*
6.2.9200.24975.*
6.2.9200.25031.*
6.2.9200.24919.*
6.2.9200.24768.*
6.2.9200.24116.*
4113.*
7378.*
R2.*
SP2.*
SP2.X64
SP2.X32
SP2.*
SP2.*
R2.SP1
R2.SP1
R2.SP1
R2.SP1
R2.SP1
Windows 10
Windows 10Microsoft
1004.*
2601.*
2478.*
2479.*
2025.*
21H22.*
24H2.*
2024.*
23H2.*
1600.*
Windows 11
Windows 11Microsoft
24H2.*
23H2.*
23H2.*
23H2.*
23H2.*
23H2.*
23H2.*
23H2.*
21H2X.*
22H2.*
Windows 7
Windows 7Microsoft
SP1.*
SP1.*
SP1.*
Gold.*
*.SP1
*.*
*.SP1
*.SP1
*.*
2010.*
WR8
6.3.9600.20520.*
*.*
*.*
*.*
-.*
-.*
-.*
Windows 8.1
Windows 8.1Microsoft
6.3.9600.20520.*
6.3.9600.20520.*
RT.*
*.*
*.*
*.*
*.*
-.*
-.*
-.*

Screenshots from the blog posts

images/clp9wm66510691for8xyfgp80.pngimages/clp9wm66510691for8xyfgp80.png

Summary

Follina is a critical RCE vulnerability in Microsoft Office products that can be exploited by opening malicious documents or viewing them in the preview pane. The maldoc uses Word's external link to load the HTML and then uses the "ms-msdt" scheme to execute PowerShell code.

Description

users/photos/clj8b3h1k16g10uoihwvzgsxi.png

@jakaba

74 posts

Total vcoins

64.3K

Social media links

Comments (1)