Gadget Page
No Result
View All Result
  • Home
  • Apps
  • Gadget Info
  • Gaming
PRICING
SUBSCRIBE
  • Home
  • Apps
  • Gadget Info
  • Gaming
No Result
View All Result
Gadget Page
No Result
View All Result
Home Uncategorized

Threatening Advice: CVE-2022-30190 ‘Folina’ – Serious Zero-Day Weakness Discovered in MSDT

gadgetpage by gadgetpage
June 3, 2022
Reading Time: 2 mins read
0
Threatening Advice: CVE-2022-30190 ‘Folina’ – Serious Zero-Day Weakness Discovered in MSDT


RELATED POSTS

Puedes descargar Age of Empires III gratis y legalmente

Vanessa Kirby will play Sue Storm in Fantastic Four

Tower of Fantasy: Einjähriges Jubiläum und großes Update 3.1 angekündigt

A zero-day remote code execution vulnerability in the Microsoft Windows Support Diagnostic Tool (MSDT) has been identified as CVE-2022-30190 “FOLLINA” with high intensity.

MSDT is a tool in Windows version 7 and above and is used to diagnose problems in applications such as MS Office documents when a user reports a problem with Microsoft support.

Why is CVE-2022-30190 “Folina” vulnerability so dangerous?

This diagnostic tool (MSDT) is typically called by applications like MS Office Documents that allow the execution of remote code with the privilege of the calling process when calling through the MSDT URL protocol. The attacker can exploit this vulnerability to run the code arbitrarily.

This vulnerability has been exploited by using MS Office documents distributed via email to run malicious payloads (e.g. Turian Backdoor, Cobalt Strike, etc.). Initially VIP Invitation at Doha Expo used WebDAV to download a sample CobaltStrike called 2023.docx (7c4ee39de1b67937a26c9bc1a7e5128b).

Chinese APT Group ‘TA413’ Wild exploits this vulnerability by downloading backdoor as payload via MSDT URL protocol.

The image below shows the base64 encoded html file downloaded by DOC (SHA 🙂 000c10fef5a643bd96da7cf3155e6a38) From hxxp: // 212[.]138.130.8 / Analysis [.]html

The following figure shows the decoded data:

When we decode base64 encoded data it is clear that svchosts.exe which is downloaded via backdoor MSDT URL PROTOCOL

Mitigation of “Folina”

Disabling MSDT URL Protocol:

  1. Run the following command as administrator to back up the registry key –

“reg export HKEY_CLASSES_ROOT \ ms-msdt filename”

  1. To delete the registry key, run the command “reg delete HKEY_CLASSES_ROOT \ ms-msdt / f”.

To restore the registry key, run the following command as administrator – “reg import filename”.

How does Quick Hill protect its customers from CVE-2022-30190 – Follina?

Quick Heal protects its customers against this vulnerability in MSDT with the following identification: –

  • Backdoor.Turian.S28183972
  • CVE-2022-30190.46635
  • CVE-2022-30190.46634
  • CVE-2022-30190.46624
  • CVE-2022-30190.46623

Quickhill



Source link

Share this:

  • Twitter
  • Facebook
ShareTweetPin
gadgetpage

gadgetpage

Related Posts

Puedes descargar Age of Empires III gratis y legalmente
Uncategorized

Puedes descargar Age of Empires III gratis y legalmente

August 4, 2023
Vanessa Kirby will play Sue Storm in Fantastic Four
Uncategorized

Vanessa Kirby will play Sue Storm in Fantastic Four

August 4, 2023
Tower of Fantasy: Einjähriges Jubiläum und großes Update 3.1 angekündigt
Uncategorized

Tower of Fantasy: Einjähriges Jubiläum und großes Update 3.1 angekündigt

August 3, 2023
OLED-Roadmap 2024: Monitorhersteller gibt Einblicke
Uncategorized

OLED-Roadmap 2024: Monitorhersteller gibt Einblicke

August 2, 2023
Samsung Galaxy SmartTag 2: Zertifizierung zeigt neues Design – Allround-PC.com
Uncategorized

Samsung Galaxy SmartTag 2: Zertifizierung zeigt neues Design – Allround-PC.com

August 2, 2023
Samsung Galaxy S23 FE: Neue Details zur Kamera
Uncategorized

Samsung Galaxy S23 FE: Neue Details zur Kamera

August 2, 2023
Next Post
Old Hacks Die Hard: Ransomware, Social Engineering Top Verification DBIR Threat – Again

Old Hacks Die Hard: Ransomware, Social Engineering Top Verification DBIR Threat - Again

IPhone 14 Pro will be the only one in the line-up with A16 bionic chip: new performance confirmation – Computermagazine.it

IPhone 14 Pro will be the only one in the line-up with A16 bionic chip: new performance confirmation - Computermagazine.it

Recommended Stories

Manchester City promoted in Japan with holograms

Manchester City promoted in Japan with holograms

July 21, 2023
Verizon’s big advantage teeters on the edge of MEC

Verizon’s big advantage teeters on the edge of MEC

March 2, 2022
The Rings of Power Suffre de Review Bombardment |  Atomics

The Rings of Power Suffre de Review Bombardment | Atomics

September 3, 2022

Popular Stories

  • Xiaomi 13T is said to have a flagship camera on board – macro rubbish thrown away

    Xiaomi 13T is said to have a flagship camera on board – macro rubbish thrown away

    0 shares
    Share 0 Tweet 0
  • Gamescom 2023: Asus Republic of Gamers event with new products and contests

    0 shares
    Share 0 Tweet 0
  • Horizon Forbidden West, new major event: all accounts

    0 shares
    Share 0 Tweet 0
  • iPhone 12 mini Review | Trusted Reviews

    0 shares
    Share 0 Tweet 0
  • Sharp Milano: City e-bike showcased at IFA 2023

    0 shares
    Share 0 Tweet 0
  • Home
  • Apps
  • Gadget Info
  • Gaming
Call us: +1 234 JEG THEME

© 2023 JNews - Premium WordPress news & magazine theme by Jegtheme.

No Result
View All Result
  • Home
  • Apps
  • Gadget Info
  • Gaming

© 2023 JNews - Premium WordPress news & magazine theme by Jegtheme.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?