---
title: Microsoft Office Follina Attack
description: A vulnerability has been identified within the Microsoft Windows Support Diagnostic Tool (MSDT) via Microsoft Office.
---

[Synivate News & Updates](https://synivate.com/blog)

# [Microsoft Office Follina Attack](https://synivate.com/blog/microsoft-follina-attack)

 Written by [Sean Maguire](https://synivate.com/blog/author/seanmaguire) | 6/1/2022

A vulnerability has been identified within the Microsoft Windows Support Diagnostic Tool (MSDT) via Microsoft Office. It is being tracked under [https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-30190](https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-30190)

From Microsoft: *A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling application. The attacker can then install programs, view, change, or delete data, or create new accounts in the context allowed by the user’s rights.*

Our security team is deploying the Microsoft recommended guidance which involves disabling the MSDT URL protocol as it is typically not used day-to-day.

**Customers with managed security services, monitoring and patching services will be scanned and patched for this vulnerability. If you have any questions, please reach out to us.**

Huntress Blog (Technical): [https://www.huntress.com/blog/microsoft-office-remote-code-execution-follina-msdt-bug](https://www.huntress.com/blog/microsoft-office-remote-code-execution-follina-msdt-bug)

[View full post](https://synivate.com/blog/microsoft-follina-attack)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Sean Maguire"
  },
  "dateModified" : "2025-03-04T00:34:51.326Z",
  "datePublished" : "2022-06-01T20:15:08Z",
  "headline" : "Microsoft Office Follina Attack",
  "image" : {
    "@type" : "ImageObject",
    "height" : 533,
    "url" : "https://7423886.fs1.hubspotusercontent-na1.net/hubfs/7423886/Imported_Blog_Media/password-safety-protocols-2.jpg",
    "width" : 800
  },
  "mainEntityOfPage" : "https://synivate.com/blog/microsoft-follina-attack",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60.0,
      "url" : "https://7423886.fs1.hubspotusercontent-na1.net/hubfs/7423886/Landing%20Page%20Assets/synivate_logo_WEB_200.png",
      "width" : 60.000004
    },
    "name" : "Synivate News & Updates"
  }
}
```