Junglewise Threat Intelligence

CVE-2022-30190: Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability

CVE-2022-30190 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-06-14

Technologies: Microsoft Windows, Microsoft Windows 11, Microsoft Windows 8.1, Microsoft Windows 7, Microsoft Windows Server, Microsoft Windows 10, Microsoft Windows Rt 8.1. Vendors: Microsoft.

Executive brief

A remote code execution vulnerability exists in the Microsoft Windows Support Diagnostic Tool (MSDT) when it is invoked via the URL protocol from applications like Microsoft Word. An attacker can exploit this to run arbitrary code with the privileges of the calling application, potentially allowing for program installation or data manipulation.

Affected products

  • Microsoft Windows 10 1507, 1607, 1809, 20H2, 21H1, 21H2
  • Microsoft Windows 11 21H2
  • Microsoft Windows Server 2008, 2012, 2016, 2019, 2022, 20H2
  • Microsoft Windows 7 SP1
  • Microsoft Windows 8.1
  • Microsoft Windows RT 8.1

Timeline

  • 2022-06-14: disclosed
  • 2022-06-14: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-06-14: patched: Patch availability indicated in MSRC advisory link
  • 2022-06-14: exploited: Reported as exploited in the wild at time of publication

Related threats