LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-30190: Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 14, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Jul 5, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-30190 to its Known Exploited Vulnerabilities catalog on Jun 14, 2022, with a federal patch deadline of Jul 5, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run code…

CVE-2022-30190 is a remote code execution vulnerability in the Microsoft Windows Support Diagnostic Tool (MSDT). When MSDT is invoked via its URL protocol from a calling application such as Word, an attacker can cause code to run with the privileges of that application. The flaw has been used in ransomware activity, so Windows environments that process untrusted documents or links need prompt attention.

Defenders should treat this as a high-priority item: confirm exposure against the vendor advisory, apply the supplied updates, and watch for signs of abuse until systems are fully remediated.

How it works

The weakness is classified as CWE-610 (Externally Controlled Reference to a Resource in Another Sphere). MSDT can be launched through a URL protocol handler from another application. An attacker who can supply a crafted reference—typically delivered through a document or similar file opened in a calling application—can cause MSDT to execute attacker-controlled actions under the privileges of that calling application rather than under a more restricted context.

Successful exploitation therefore yields code execution at the privilege level of the user or process that opened the malicious file. Exact invocation details and payload formats must be confirmed against the vendor advisory; do not rely on third-party write-ups alone for detection logic.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Windows systems that include the Support Diagnostic Tool and its URL protocol handler. MSDT is a built-in component on supported Windows releases, so inventory should focus on Windows endpoints and servers that run office productivity software or otherwise open untrusted files.

Specific affected builds and fixed versions are listed only in the vendor advisory—verify there before declaring a host clean.

How to remediate

Patch first. Apply the updates Microsoft released for CVE-2022-30190 according to the vendor instructions and CISA’s required action. Use your standard deployment ring (test, then production) and confirm installation via update compliance reports.

If you can't patch immediately

Until the vendor update can be deployed, reduce risk with compensating controls:

If your data may have been exposed

Actively exploited vulnerabilities, including those with known ransomware use, frequently precede broader compromise and data theft. If you have indicators of exploitation or ransomware activity, follow your incident-response plan: isolate affected hosts, preserve evidence, and assess whether credentials or data left the environment. You can also run a free exposure scan of your email addresses against known breach data to see whether associated accounts appear in prior dumps and then prioritize password resets and monitoring accordingly.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-610
Added to CISA KEVJun 14, 2022
Federal patch deadlineJul 5, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities