CVE-2022-30190CISA KEV
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run code with the privileges of the calling application.
- Product
- Windows
- Added to KEV
- 14 Jun 2022
- Federal remediation due
- 5 Jul 2022
- Known ransomware use
- Yes