Published on: 31 May 2022
Last update on: 07 June 2022
Microsoft has released an out-of-band security advisory to address the vulnerability in Microsoft Diagnostic Tool (MSDT) being called via the URL protocol from a calling application such as Word. An attacker exploiting the vulnerability could install programs, view, change, delete data, or create new accounts in the context allowed by the user’s rights.
Reports indicate that a remote code execution vulnerability (CVE-2022-30190) in Microsoft Windows and Server is being actively exploited. Patches are yet to be available but Microsoft has provided a workaround to mitigate the risk. System administrators are advised to observe the advisory and immediately apply the recommended workaround to mitigate the elevated risk of cyber attacks.
A successful attack could lead to remote code execution on an affected system.
While patches for affected products are yet available, temporary measure is provided by Microsoft to mitigate the risk of exploitation. Users of affected systems should follow the provided recommendation in the following URL and take immediate actions to mitigate the risk.
https://msrc-blog.microsoft.com/2022/05/30/guidance-for-cve-2022-30190-microsoft-support-diagnostic-tool-vulnerability/