All insights

Follina (CVE-2022-30190): Current Status and Remediation

A white Office logo with an orange background

Microsoft patched Follina in June 2022 and added defense-in-depth updates in July. Review the attack path, current remediation, and validation steps.

Published May 31, 2022Updated July 15, 20265 min readBy Daniel Foster

Historical advisory — reviewed July 15, 2026. Microsoft released Windows security updates for CVE-2022-30190 on June 14, 2022, followed by defense-in-depth updates in the July 2022 cumulative releases. The registry workaround in the original version of this advisory is not a substitute for patching. Organizations should run supported Windows versions and install current cumulative security updates.

Executive summary

Follina, tracked as CVE-2022-30190, is a remote code execution vulnerability in the Microsoft Support Diagnostic Tool (MSDT). An attacker could use a malicious document or another calling application to invoke the ms-msdt: URL protocol and run code with the privileges of the affected application.

Microsoft released updates addressing the vulnerability on June 14, 2022 and added a defense-in-depth fix to the July 2022 cumulative updates. CISA added CVE-2022-30190 to its Known Exploited Vulnerabilities Catalog and directs organizations to apply vendor updates.

The practical response today is straightforward: identify devices that missed the updates, bring supported Windows systems to a current cumulative patch level, remove or isolate unsupported systems, and investigate any evidence that exploitation occurred before patching. Installing an update prevents the vulnerable path from being used; it does not remove an attacker who already established access.

How the original attack worked

The attack observed in 2022 commonly began with a malicious Microsoft Office document. The document referenced remote HTML content, which used the ms-msdt: URL protocol to invoke MSDT with attacker-controlled parameters. That process could then launch additional commands or scripts, including PowerShell, without relying on Office macros.

The simplified attack chain was:

  1. A user opened or previewed a malicious Office document.
  2. The document retrieved attacker-controlled HTML content.
  3. The HTML invoked the ms-msdt: URL protocol.
  4. MSDT processed attacker-controlled arguments and executed code in the calling application's security context.
  5. The attacker could install programs, access or alter data, or create accounts within the affected user's permissions.

Disabling VBA macros did not address this path because the exploit did not depend on a macro. Microsoft also documented that Protected View and Application Guard for Office prevented the attack scenarios it had observed when Office opened internet-sourced documents using those protections.

Current patch status

Microsoft's June 14, 2022 Windows updates addressed CVE-2022-30190. Microsoft then included a defense-in-depth fix for a related variant in the July 2022 cumulative updates. Supported Windows 10 and newer systems receive those protections through cumulative servicing; older supported products at the time required the applicable updates identified by Microsoft.

Organizations should not use the old registry deletion workaround as their primary long-term control. The workaround was published before patches were available and disabled the MSDT URL protocol by deleting its handler. Current remediation is to install vendor security updates and keep Windows on a supported release.

Systems remain a concern when they:

  • Missed the June and July 2022 updates and subsequent cumulative updates.
  • Run an unsupported Windows release that no longer receives security fixes.
  • Are excluded from normal patch management or have not reported update status.
  • Show evidence of suspicious Office, MSDT, script, or child-process activity that predates patching.

Response and validation steps

Patch supported Windows systems

Use the Microsoft Security Update Guide entry for CVE-2022-30190 to identify the affected products and original fixed versions. For systems still in service, deploy the latest applicable cumulative Windows security update rather than stopping at the original 2022 package.

Replace or isolate unsupported operating systems. A successful scan for one historical KB is not enough if the device has since fallen behind on cumulative updates.

Confirm deployment

Validate patch status through the organization's endpoint management or vulnerability management platform. Review systems that have stopped checking in, failed installation, are pending restart, or fall outside the normal update ring. Rescan after remediation and retain evidence of the completed deployment.

Hunt for exploitation

Review available endpoint and security telemetry for suspicious behavior associated with the original attack path, including:

  • Office applications spawning msdt.exe, PowerShell, cmd.exe, or other unexpected child processes.
  • Suspicious MSDT command lines or use of the ms-msdt: protocol.
  • Script or payload downloads immediately after an Office document was opened.
  • Microsoft Defender alerts such as Suspicious behavior by an Office application, Suspicious behavior by Msdt.exe, or Possible exploitation attempt of CVE-2022-30190.
  • Follow-on account creation, persistence, credential access, or lateral movement.

A matching process or alert should be investigated in context; it is not by itself proof that a system was compromised. If evidence indicates successful execution, preserve relevant logs and artifacts, isolate the host, reset affected credentials and sessions, and follow the organization's incident response process.

Review any legacy workaround

If the organization deleted the MSDT URL handler as an emergency workaround in 2022, document which systems received that change. Do not restore the handler until patch status has been confirmed and the operational need is understood. Microsoft's original guidance documents both the workaround and its reversal, but current cumulative updates remain the primary remediation.

Maintain defense in depth

Keep Microsoft Defender or the organization's equivalent endpoint protections current. Where applicable, use cloud-delivered protection, Office Safe Attachments and Safe Links, Protected View, Application Guard, and attack surface reduction rules. These controls can reduce the chance that a malicious document or its follow-on activity succeeds, but they do not replace operating system patching.

How CulperSec can help

CulperSec can help organizations verify exposure, prioritize remediation, hunt for suspicious endpoint activity, and respond when evidence suggests exploitation. Learn more about Managed Vulnerability Management or request Incident Response support.

Sources

About the author

Continue reading

More perspectives

View the archive

Put insight to work

Bring the right security expertise to the next decision.

Tell us what your organization is facing. We will help define the practical next step.

Start a conversation