Cybersecurity Alerts

Actively Exploited Vulnerabilities

← Back to Cybersecurity Alerts

CVE-2022-30190

Microsoft | WindowsAdded 2022-06-14Remediation Deadline 2022-07-05Active Ransomware Campaign

Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability

A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run code with the privileges of the calling application.

Required Action

Apply updates per vendor instructions.

Weakness Classification

CWE-610

References