CVE-2022-30190: Follina
A remote code execution vulnerability reached through the Windows Support Diagnostic Tool (MSDT), triggered when an application such as Microsoft Word invokes MSDT via the ms-msdt URI scheme. A malicious Office document can trigger it without macros enabled, letting the attacker run PowerShell as the current user.
View the authoritative record on NVD ↗Affected software
- Microsoft Windows Support Diagnostic Tool (MSDT) across supported Windows and Office versions (2022)
How it's exploited
Send a Word document referencing an external OLE object over HTTP; the object's ms-msdt: link launches MSDT and passes it a crafted PowerShell command, which can execute even with macros and Protected View disabled.
Severity
CVE-2022-30190 carries a CVSS 3.1 base score of 7.8, rated High. See how CVSS scoring works or score a vulnerability yourself with the free CVSS calculator.
Weakness type
CVE-2022-30190 is categorized under CWE-20, the general weakness pattern behind this specific vulnerability.
Where this fits in a TurboPentest engagement
TurboPentest's agentic pentest is powerful and covers a broad range of issues automatically. This particular class is best confirmed in a manual IntegSec engagement, where human pentesters apply deeper methodology and a larger context window than any automated pass.
Remediation
Apply Microsoft's June 2022 security update, or the interim workaround of disabling the MSDT URL protocol handler if patching must wait.
Frequently asked questions
What is CVE-2022-30190?
A remote code execution vulnerability reached through the Windows Support Diagnostic Tool (MSDT), triggered when an application such as Microsoft Word invokes MSDT via the ms-msdt URI scheme. A malicious Office document can trigger it without macros enabled, letting the attacker run PowerShell as the current user.
How severe is CVE-2022-30190?
CVE-2022-30190 has a CVSS 3.1 base score of 7.8 out of 10, rated High.
What software is affected by CVE-2022-30190?
CVE-2022-30190 affects Microsoft Windows Support Diagnostic Tool (MSDT) across supported Windows and Office versions (2022).
How do you fix CVE-2022-30190?
Apply Microsoft's June 2022 security update, or the interim workaround of disabling the MSDT URL protocol handler if patching must wait.
Where is the authoritative record for CVE-2022-30190?
The National Vulnerability Database (NVD) publishes the authoritative record for CVE-2022-30190 at https://nvd.nist.gov/vuln/detail/CVE-2022-30190, including the current CVSS score, CWE mapping, and affected-configuration data.
Related CVEs
About this reference
These security references are maintained by IntegSec, an offensive-security firm whose team holds CISSP, OSCP, and OSCE certifications and has run thousands of penetration tests. Content is kept current as tools, standards, and attack techniques evolve.
Find known-vulnerable services before an attacker does
TurboPentest fingerprints every open port and web service, then matches detected versions against known CVEs automatically, from $99 per target.
Start a pentest