Executive brief
A remote code execution vulnerability exists in the Microsoft Windows Support Diagnostic Tool (MSDT) when it is invoked via the URL protocol from a calling application. An attacker can exploit this by tricking a user into opening a specially crafted file or link, leading to code execution with the privileges of the calling application.
Affected products
- Microsoft Windows 10 up to (excluding) 10.0.19044.1889
- Microsoft Windows 11 up to (excluding) 10.0.22000.856
- Microsoft Windows Server 2022 up to (excluding) 10.0.20348.887
- Microsoft Windows 7 SP1
- Microsoft Windows 8.1
- Microsoft Windows Server 2008 R2 SP1
- Microsoft Windows Server 2012
- Microsoft Windows Server 2016 up to (excluding) 10.0.14393.5291
- Microsoft Windows Server 2019 up to (excluding) 10.0.17763.3287
Timeline
- 2022-08-09: disclosed
- 2022-08-09: patched
- 2022-08-09: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-08-09: exploited: Reported as exploited in the wild at time of publication.