A zero-day Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability (CVE-2022-30190), also known as "Follina", has been identified when MSDT is called using the URL protocol from a calling application such as Word. As explained in the MSRC Blog Entry, an attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling application. The attacker can then install programs, view, change, or delete data, or create new accounts in the context allowed by the user?s rights.
In relation to this vulnerability, Panda Endpoint Security products can detect and block these attacks conducted via this exploit as Exploit/CVE-2022-30190:
We recommend that you apply the mitigations described by Microsoft to minimize the impact of this vulnerability.