CVE-2022-30190

Exploited in the Wild ✓ Confirmed 0-Day ★ Google Project Zero
Triaged: March 3, 2026 21 articles

EPSS Score

Source: FIRST.org · 2026-05-24
93.53%
probability
This CVE has a 93.53% probability of being exploited in the next 30 days.
0% Top 99.8th percentile of all CVEs 100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE. View on VulnerabilityLookup ↗

Description

Project Zero
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability

Google Project Zero

Patched
June 14, 2022
Reported by
crazyman with Shadow Chaser Group
Root Cause Analysis
???

Exploits & PoC

komomon/CVE-2022-30190-follina-Office-MSDT-Fixed

CVE-2022-30190-follina.py-修改版,可以自定义word模板,方便实战中钓鱼使用。

393
JMousqueton/PoC-CVE-2022-30190

POC CVE-2022-30190 : CVE 0-day MS Offic RCE aka msdt follina

158
Malwareman007/Deathnote

Proof of Concept of CVE-2022-30190

38
Hrishikesh7665/Follina_Exploiter_CLI

Exploit Microsoft Zero-Day Vulnerability Follina (CVE-2022-30190)

33
MalwareTech/FollinaExtractor

Extract payload URLs from Follina (CVE-2022-30190) docx and rtf files

31
ErrorNoInternet/FollinaScanner

A tool written in Go that scans files & directories for the Follina exploit (CVE-2022-30190)

23
Noxtal/follina

All about CVE-2022-30190, aka follina, that is a RCE vulnerability that affects Microsoft Support Diagnostic Tools (MSDT) on Office apps such as Word.

22
7 repos — triés par ⭐ Rechercher sur GitHub ↗
Security Advisory 2022-039
CERT-EU May 30, 2022
Security Advisory 2022-042
CERT-EU Jun 15, 2022

Signal Intelligence

Confidence
92%
EPSS 93.53%
Mentions 21
Last Seen May 27, 2026

CNA Information

Analyst Note

CVE-2022-30190 (Follina) is a well-documented remote code execution vulnerability affecting Microsoft Office through the MSDT protocol handler, with high CVSS score (7.8) and confirmation by Google Project Zero. Multiple security advisories from CERT-EU and widespread coverage substantiate the vulnerability's authenticity and severity in real-world exploitation scenarios.

Threat Actors 47

Lazarus Group
apt_group Information theft and espionage 🇰🇵 KP
Turla Group
apt_group Information theft and espionage Russian Federation
APT 29
apt_group Information theft and espionage 🇷🇺 RU
Mustang Panda
apt_group Information theft and espionage 🇨🇳 CN
WIZARD SPIDER
apt_group Financial gain 🇷🇺 RU
Cobalt
apt_group Financial crime 🇷🇺 RU
FIN7
apt_group Financial crime 🇷🇺 RU
Kimsuky
apt_group Information theft and espionage 🇰🇷 KR
SaintBear
apt_group Information theft and espionage 🇷🇺 RU
MageCart
apt_group Financial gain 🇷🇺 RU
CHRYSENE
apt_group Information theft and espionage 🇮🇷 IR
Vicious Panda
apt_group Information theft and espionage 🇨🇳 CN
Harvester
apt_group Information theft and espionage Unknown
Leviathan
apt_group Information theft and espionage 🇨🇳 CN
BelialDemon
apt_group 🇷🇺 RU
Ghostwriter
apt_group 🇧🇾 BY
MAGNALLIUM
apt_group Sabotage and destruction 🇮🇷 IR
GOLD PRELUDE
apt_group 🇷🇺 RU
Kinsing
apt_group 🇷🇺 RU
Tick
apt_group Information theft and espionage 🇨🇳 CN
HAZY TIGER
apt_group Information theft and espionage 🇮🇳 IN
TA505
apt_group Financial gain 🇷🇺 RU
Infy
apt_group Information theft and espionage 🇮🇷 IR
TA570
apt_group 🇷🇺 RU
TeamTNT
apt_group 🇩🇪 DE
Lucky Cat
apt_group Information theft and espionage 🇨🇳 CN
TA428
apt_group Information theft and espionage 🇨🇳 CN
Callisto
apt_group Information theft and espionage 🇷🇺 RU
Pirate Panda
apt_group Information theft and espionage 🇨🇳 CN
Storm-2077
apt_group Information theft and espionage 🇨🇳 CN
TAG-100
apt_group Information theft and espionage 🇨🇳 CN
TA413
apt_group Information theft and espionage 🇨🇳 CN
RomCom
apt_group Financial gain 🇷🇺 RU
FIN8
apt_group Financial crime 🇷🇺 RU
APT31
apt_group Information theft and espionage 🇨🇳 CN
POLONIUM
apt_group Information theft and espionage 🇱🇧 LB
APT 22
apt_group Information theft and espionage 🇨🇳 CN
Rocke
apt_group 🇨🇳 CN
RedAlpha
apt_group Information theft and espionage 🇨🇳 CN
Bitwise Spider
apt_group Financial gain 🇷🇺 RU
Pat Bear
apt_group 🇸🇾 SY
Gelsemium
apt_group Information theft and espionage 🇨🇳 CN
Shadow Network
apt_group Information theft and espionage 🇨🇳 CN
Operation Olympic Games
apt_group Sabotage and destruction 🇺🇸 US
Mana Team
apt_group 🇨🇳 CN
Operation Shadow Force
apt_group 🇨🇳 CN
Operation Black Atlas
apt_group Financial crime

Triage Info

Decided atMar 03, 2026