What happened
A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run code with the privileges of the calling application.
Affected versions
Windows: See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
PoC-in-GitHub · JMousqueton/PoC-CVE-2022-30190POC CVE-2022-30190 : CVE 0-day MS Offic RCE aka msdt follina★ 157JMousqueton2022-05-30CandidatePoC-in-GitHub · onecloudemoji/CVE-2022-30190CVE-2022-30190 Follina POC★ 104onecloudemoji2022-05-31CandidatePoC-in-GitHub · 2867a0/CVE-2022-30190★ 02867a02022-05-31CandidatePoC-in-GitHub · doocop/CVE-2022-30190Microsoft Office Word Rce 复现(CVE-2022-30190)★ 59doocop2022-05-31CandidatePoC-in-GitHub · archanchoudhury/MSDT_CVE-2022-30190This Repository Talks about the Follina MSDT from Defender Perspective★ 37archanchoudhury2022-05-31CandidatePoC-in-GitHub · rickhenderson/cve-2022-30190Aka Follina = benign POC.★ 1rickhenderson2022-05-31CandidatePoC-in-GitHub · DOV3Y/CVE-2022-30190-ASR-Senintel-Process-PickupPicking up processes that have triggered ASR related to CVE-2022-30190★ 0DOV3Y2022-05-31CandidatePoC-in-GitHub · kdk2933/msdt-CVE-2022-30190CVE-2022-30190- A Zero-Click RCE Vulnerability In MSDT★ 1kdk29332022-05-31CandidatePoC-in-GitHub · sentinelblue/CVE-2022-30190Microsoft Sentinel analytic rule and hunting queries in ASIM for activity of MSDT and CVE-2022-30190.★ 5sentinelblue2022-05-31CandidatePoC-in-GitHub · aymankhder/MSDT_CVE-2022-30190-follina-★ 0aymankhder2022-05-31CandidatePoC-in-GitHub · PaddlingCode/cve-2022-30190CVE-2022-30190 remediation via removal of ms-msdt from Windows registry★ 6PaddlingCode2022-05-31CandidatePoC-in-GitHub · dwisiswant0/gollinaFollina MS-MSDT 0-day MS Office RCE (CVE-2022-30190) PoC in Go★ 17dwisiswant02022-06-01CandidatePoC-in-GitHub · hscorpion/CVE-2022-30190★ 0hscorpion2022-06-01CandidatePoC-in-GitHub · drgreenthumb93/CVE-2022-30190-follinaJust another PoC for the new MSDT-Exploit★ 8drgreenthumb932022-06-01CandidatePoC-in-GitHub · mitespsoc/CVE-2022-30190-POC★ 0mitespsoc2022-06-01CandidatePoC-in-GitHub · Vaisakhkm2625/MSDT-0-Day-CVE-2022-30190-Poc★ 0Vaisakhkm26252022-06-01CandidatePoC-in-GitHub · rouben/CVE-2022-30190-NSISAn NSIS script that helps deploy and roll back the mitigation registry patch for CVE-2022-30190 as recommended by Microsoft★ 3rouben2022-06-01CandidatePoC-in-GitHub · Cosmo121/Follina-RemediationRemoves the ability for MSDT to run, in response to CVE-2022-30190 (Follina)★ 4Cosmo1212022-06-01CandidatePoC-in-GitHub · rayorole/CVE-2022-30190CVE-2022-30190 or "Follina" 0day proof of concept★ 0rayorole2022-06-01CandidatePoC-in-GitHub · ImproveCybersecurityJaro/2022_PoC-MSDT-Follina-CVE-2022-30190Proof of Concept zu MSDT-Follina - CVE-2022-30190. ÜBERPRÜFUNG DER WIRKSAMKEIT VON MICROSOFT DEFNEDER IN DER JEWEILS AKTUELLSTEN WINDOWS 10 VERSION.★ 0ImproveCybersecurityJaro2022-06-01CandidatePoC-in-GitHub · sudoaza/CVE-2022-30190MS-MSDT Follina CVE-2022-30190 PoC document generator★ 7sudoaza2022-06-01CandidatePoC-in-GitHub · gamingwithevets/msdt-disableMSDT protocol disabler (CVE-2022-30190 patch tool)★ 2gamingwithevets2022-06-02CandidatePoC-in-GitHub · ErrorNoInternet/FollinaScannerA tool written in Go that scans files & directories for the Follina exploit (CVE-2022-30190)★ 23ErrorNoInternet2022-06-02CandidatePoC-in-GitHub · ITMarcin2211/CVE-2022-30190★ 1ITMarcin22112022-06-02CandidatePoC-in-GitHub · derco0n/mitigate-folinaMitigates the "Folina"-ZeroDay (CVE-2022-30190)★ 1derco0n2022-06-02CandidatePoC-in-GitHub · komomon/CVE-2022-30190-follina-Office-MSDT-FixedCVE-2022-30190-follina.py-修改版,可以自定义word模板,方便实战中钓鱼使用。★ 391komomon2022-06-02CandidatePoC-in-GitHub · gyaansastra/CVE-2022-30190★ 2gyaansastra2022-06-02CandidatePoC-in-GitHub · swaiist/CVE-2022-30190-Fix★ 2swaiist2022-06-02CandidatePoC-in-GitHub · suenerve/CVE-2022-30190-Follina-PatchThe CVE-2022-30190-follina Workarounds Patch★ 2suenerve2022-06-02CandidatePoC-in-GitHub · castlesmadeofsand/ms-msdt-vulnerability-pdq-packagePDQ Package I created for CVE-2022-30190★ 0castlesmadeofsand2022-06-02CandidatePoC-in-GitHub · WesyHub/CVE-2022-30190---Follina---Poc-ExploitSimple Follina poc exploit★ 0WesyHub2022-06-02CandidatePoC-in-GitHub · 0xflagplz/MS-MSDT-Office-RCE-FollinaCVE-2022-30190 | MS-MSDT Follina One Click★ 200xflagplz2022-06-02CandidatePoC-in-GitHub · arozx/CVE-2022-30190A very simple MSDT "Follina" exploit **patched**★ 2arozx2022-06-02CandidatePoC-in-GitHub · Noxtal/follinaAll about CVE-2022-30190, aka follina, that is a RCE vulnerability that affects Microsoft Support Diagnostic Tools (MSDT) on Office apps such as Word. This is a very simple POC, feel free to check the sources below for more threat intelligence.★ 21Noxtal2022-06-03CandidatePoC-in-GitHub · droidrzrlover/CVE-2022-30190This is to patch CVE-2022-30190. Use at your own risk.★ 0droidrzrlover2022-06-03CandidatePoC-in-GitHub · hilt86/cve-2022-30190-mitigatePowershell script to mitigate cve-2022-30190★ 0hilt862022-06-03CandidatePoC-in-GitHub · SrikeshMaharaj/CVE-2022-30190Follina POC by John Hammond★ 2SrikeshMaharaj2022-06-03CandidatePoC-in-GitHub · AbdulRKB/FollinaDemonstration of Windows MSDT Vulnerability (CVE-2022-30190)★ 5AbdulRKB2022-06-04CandidatePoC-in-GitHub · DerZiad/CVE-2022-30190This project demonstrates a proof-of-concept exploit for CVE-2022-30190, also known as "Follina"—a critical remote code execution vulnerability affecting Microsoft Office via the MSDT protocol. The application generates malicious Office documents to illustrate the exploit workflow for educational and research purposes only.★ 6DerZiad2022-06-04CandidatePoC-in-GitHub · tej7gandhi/CVE-2022-30190-Zero-Click-Zero-Day-in-msdt★ 0tej7gandhi2022-06-05CandidatePoC-in-GitHub · ItsNee/Follina-CVE-2022-30190-POC★ 6ItsNee2022-06-05CandidatePoC-in-GitHub · IamVSM/msdt-follinaMicrosoft MS-MSDT Follina (0-day Vulnerability) CVE-2022-30190 Attack Vector★ 1IamVSM2022-06-06CandidatePoC-in-GitHub · joshuavanderpoll/CVE-2022-30190Microsoft Support Diagnostic Tool (CVE-2022-30190)★ 2joshuavanderpoll2022-06-07CandidatePoC-in-GitHub · abhirules27/FollinaNotes related to CVE-2022-30190★ 0abhirules272022-06-07CandidatePoC-in-GitHub · dsibilio/follina-springServer to host/activate Follina payloads & generator of malicious Word documents exploiting the MS-MSDT protocol. (CVE-2022-30190)★ 4dsibilio2022-06-07CandidatePoC-in-GitHub · Malwareman007/DeathnoteProof of Concept of CVE-2022-30190★ 38Malwareman0072022-06-08CandidatePoC-in-GitHub · sentrium-security/Follina-Workaround-CVE-2022-30190★ 0sentrium-security2022-06-08CandidatePoC-in-GitHub · Hrishikesh7665/Follina_Exploiter_CLIExploit Microsoft Zero-Day Vulnerability Follina (CVE-2022-30190)★ 34Hrishikesh76652022-06-09CandidatePoC-in-GitHub · b401/Clickstudio-compromised-certificateRepository containing the compromised certificate seen in recent CVE-2022-30190 (Follina) attacks.★ 1b4012022-06-09CandidatePoC-in-GitHub · cyberdashy/CVE-2022-30190Mitigation for CVE-2022-30190★ 0cyberdashy2022-06-10CandidatePoC-in-GitHub · amitniz/follina_cve_2022-30190proof of concept to CVE-2022-30190 (follina)★ 2amitniz2022-06-10CandidatePoC-in-GitHub · Abdibimantara/CVE-2022-30190-Analysis-With-LetsDefends-Labthis is my simple article about CVE 2022-30190 (Follina) analysis. I use the lab from Letsdefend.★ 0Abdibimantara2022-06-10CandidatePoC-in-GitHub · JotaQC/CVE-2022-30190_Temporary_FixThese are two Python scripts compiled to easily and quickly apply temporary protection against the CVE-2022-30190 vulnerability (Follina)★ 0JotaQC2022-06-11CandidatePoC-in-GitHub · JotaQC/CVE-2022-30190_Temporary_Fix_Source_CodeThese are the source codes of the Python scripts to apply the temporary protection against the CVE-2022-30190 vulnerability (Follina)★ 0JotaQC2022-06-12CandidatePoC-in-GitHub · SonicWave21/Follina-CVE-2022-30190-Unofficial-patchAn Unofficial Patch Follina CVE-2022-30190 (patch) by micrisoft Guidelines.★ 2SonicWave212022-06-13CandidatePoC-in-GitHub · nanaao/PicusSecurity4.Week.RepoCVE-2022-30190 : CVE 0-day MS Offic RCE aka msdt follina★ 0nanaao2022-06-13CandidatePoC-in-GitHub · ernestak/CVE-2022-30190★ 0ernestak2022-06-14CandidatePoC-in-GitHub · ernestak/Sigma-Rule-for-CVE-2022-30190★ 0ernestak2022-06-14CandidatePoC-in-GitHub · MalwareTech/FollinaExtractorExtract payload URLs from Follina (CVE-2022-30190) docx and rtf files★ 31MalwareTech2022-06-15CandidatePoC-in-GitHub · notherealhazard/follina-CVE-2022-30190★ 0notherealhazard2022-06-15CandidatePoC-in-GitHub · Cerebrovinny/follina-CVE-2022-30190follina zero day vulnerability to help Microsoft to mitigate the attack★ 0Cerebrovinny2022-06-15CandidatePoC-in-GitHub · Zitchev/go_follinaFollina (CVE-2022-30190) proof-of-concept★ 2Zitchev2022-06-27CandidatePoC-in-GitHub · Gra3s/CVE-2022-30190_EXP_PowerPointThis is exploit of CVE-2022-30190 on PowerPoint.★ 8Gra3s2022-06-29CandidatePoC-in-GitHub · EkamSinghWalia/Follina-MSDT-Vulnerability-CVE-2022-30190-Detection and Remediation of the Follina MSDT Vulnerability (CVE-2022-30190)★ 3EkamSinghWalia2022-07-21CandidatePoC-in-GitHub · jeffreybxu/five-nights-at-follina-sA Fullstack Academy Cybersecurity project examining the full cycle of the Follina (CVE-2022-30190) vulnerability, from exploit to detection and defense.★ 2jeffreybxu2022-08-01CandidatePoC-in-GitHub · winstxnhdw/CVE-2022-30190A proof of concept for CVE-2022-30190 (Follina).★ 2winstxnhdw2022-09-15CandidatePoC-in-GitHub · Imeneallouche/Follina-attack-CVE-2022-30190-this is a demo attack of FOLLINA exploit , a vulnerability that has been discovered in May 2022 and stood unpatched until June 2022★ 0Imeneallouche2022-10-06CandidatePoC-in-GitHub · mattjmillner/CVE-SmackdownImplementation of CVE-2022-30190 in C★ 0mattjmillner2022-11-10CandidatePoC-in-GitHub · abbarhissarh/FollinaXploitA Command Line based python tool for exploit Zero-Day vulnerability in MSDT (Microsoft Support Diagnostic Tool) also know as 'Follina' CVE-2022-30190.★ 8abbarhissarh2022-11-19CandidatePoC-in-GitHub · Nyx2022/Follina-CVE-2022-30190-SampleEducational Follina PoC Tool★ 0Nyx20222022-12-12CandidatePoC-in-GitHub · michealadams30/Cve-2022-30190★ 1michealadams302022-12-26CandidatePoC-in-GitHub · melting0256/Enterprise-CybersecurityCVE-2022-30190(follina)★ 1melting02562022-12-29CandidatePoC-in-GitHub · yrkuo/CVE-2022-30190★ 0yrkuo2023-02-13CandidatePoC-in-GitHub · ToxicEnvelope/FOLLINA-CVE-2022-30190Implementation of FOLLINA-CVE-2022-30190★ 1ToxicEnvelope2023-03-14CandidatePoC-in-GitHub · hycheng15/CVE-2022-30190An exploitation of CVE-2022-30190 (Follina)★ 1hycheng152023-05-02CandidatePoC-in-GitHub · aminetitrofine/CVE-2022-30190Follina (CVE-2022-30190) is a Microsoft Office zero-day vulnerability that has recently been discovered. It’s a high-severity vulnerability that hackers can leverage for remote code execution (RCE) attacks.★ 12aminetitrofine2023-05-14CandidatePoC-in-GitHub · Muhammad-Ali007/Follina_MSDT_CVE-2022-30190★ 1Muhammad-Ali0072023-07-17CandidatePoC-in-GitHub · Jump-Wang-111/AmzWordAn automated attack chain based on CVE-2022-30190, 163 email backdoor, and image steganography.★ 1Jump-Wang-1112023-11-28CandidatePoC-in-GitHub · shri142/ZipScanA tool written in Go that scans files & directories for the Follina exploit (CVE-2022-30190)★ 0shri1422024-02-17CandidatePoC-in-GitHub · alienkeric/CVE-2022-30190The script is from https://github.com/JohnHammond/msdt-follina, just make it simple for me to use it and this script aim at generating the payload for more information refer the johnn hammond link★ 1alienkeric2024-04-09CandidatePoC-in-GitHub · ethicalblue/Follina-CVE-2022-30190-SampleEducational exploit for CVE-2022-30190★ 0ethicalblue2024-07-20CandidatePoC-in-GitHub · Potato-9257/CVE-2022-30190_pagePoC of CVE-2022-30190★ 0Potato-92572025-02-07CandidatePoC-in-GitHub · yeep1115/ICT287_CVE-2022-30190_ExploitProject on CVE-2022-30190 exploitation and mitigation strategies★ 0yeep11152025-03-02CandidatePoC-in-GitHub · RathoreAbhiii/Folina-Vulnerability-Exploitation-Detection-and-MitigationProject Repository for Exploitation, Detection and Mitigation of Folina Vulnerability (CVE-2022-30190)★ 0RathoreAbhiii2025-04-08CandidatePoC-in-GitHub · seinab-ibrahim/Follina-Vulnerability-CVE-2022-30190-Exploit-AnalysisExploration of the Follina (CVE-2022-30190) Microsoft Office vulnerability, including a detailed analysis, proof-of-concept exploitation in a controlled lab, and mitigation strategies. For educational and research purposes only.★ 0seinab-ibrahim2025-08-14CandidatePoC-in-GitHub · Arkha-Corvus/LetsDefend-SOC173-Follina-0-Day-DetectedWe are presented with a security alert indicating the detection of the Follina (CVE-2022-30190) vulnerability. A malicious Word document triggered msdt.exe execution, suggesting possible remote code execution on the host JonasPRD. Our task is to investigate the alert, confirm exploitation, assess impact, and recommend remediation.★ 0Arkha-Corvus2025-10-18CandidatePoC-in-GitHub · nimesh895/Malware-Analysis-Follina-CVE-2022-30190★ 0nimesh8952026-01-21CandidatePoC-in-GitHub · bcarrulo/Lab-CVE-2022-30190★ 0bcarrulo2026-02-28CandidatePoC-in-GitHub · ImVihanga03/Static-Malware-Analysis-Follina-CVE-2022-30190Static Malware Analysis of Follina (CVE-2022-30190) from Blue Team Labs Online★ 1ImVihanga032026-03-25CandidatePoC-in-GitHub · shndnth/CVE-2022-30190Educational Proof-of-Concept for the CVE-2022-30190 (Follina) vulnerability.★ 0shndnth2026-04-10CandidatePoC-in-GitHub · u1tr0nex/CVE-2022-30190-Follina-LabFull exploit chain lab and Suricata IDS detection for CVE-2022-30190 (Follina) - MSDT RCE★ 0u1tr0nex2026-05-08CandidatePoC-in-GitHub · kaleth4/CVE-2022-30190★ 0kaleth42026-06-14CandidatePoC-in-GitHub · czabatta/THM-TempestTryHackMe SOC Level 1 — Follina CVE-2022-30190, Nim C2, Chisel, PrintSpoofer, backdoor accounts★ 0czabatta2026-06-15CandidatePoC-in-GitHub · zavikhttak/follina-msdt-threat-investigation🔵 Threat analysis writeup for Follina (CVE-2022-30190) — Microsoft MSDT RCE zero-day exploited in the wild. Covers static analysis, VirusTotal, OSINT, MITRE ATT&CK T1059, and detection engineering using Windows Event ID 4688.★ 0zavikhttak2026-07-21CandidateSource timeline
Discovered through CISA Known Exploited VulnerabilitiesView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.