CVE-2022-30190General(microsoft / windows_10_1507)

HIGHCVSS 7.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for microsoft windows_10_1507 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling application. The attacker can then install programs, view, change, or delete data, or create new accounts in the context allowed by the user’s rights. Please see the MSRC Blog Entry for important information about steps you can take to protect your system from this vulnerability.

7.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-07-05. Apply updates per vendor instructions.

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1507
  • windows_10_1607
  • windows_10_1809
  • windows_10_20h2

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • 6 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • General: 3 classified signals
  • Peaked 5d ago at 1 mentions (2026-03-10); latest day: 1
  • 6 total mentions across 6 days

Affected systems

Vendors
Products
windows_10_1507windows_10_1607windows_10_1809windows_10_20h2windows_10_21h1windows_10_21h2windows_11_21h2windows_7windows_8.1windows_rt_8.1

2 versions affected across 16 products

Deep dive

Activity timeline6 mentions / 6d
00111Mentions · 2026-03-10: 1Mentions · 2026-04-03: 1Mentions · 2026-04-06: 1Mentions · 2026-04-12: 1Mentions · 2026-05-15: 1Mentions · 2026-09-07: 1PoC Mentioned / Linked · 2026-09-07: 1Exploit Tool / Code · 2026-04-06: 1Active Exploitation · 2026-04-03: 1Active Exploitation · 2026-04-12: 1Technical Details · 2026-03-10: 1Technical Details · 2026-04-03: 1Technical Details · 2026-04-12: 103-1004-0304-0604-1205-1509-07
Signal classification3 categories
General
350.0%
Active Exploitation
233.3%
PoC
116.7%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-101
General1
2026-04-031
Active Exploitation1
2026-04-061
General1
2026-04-121
Active Exploitation1
2026-05-151
General1
2026-09-071
PoC1
Full discourse6 posts
  • Napa County Corruption 🕵@NapaCorruption
    PoC

    I just completed Follina MSDT room on TryHackMe! A walkthrough on the CVE-2022-30190, the MSDT service, exploitation of the service vulnerability, and consequent detection techniques and remediation processes https://tryhackme.com/room/follinamsdt?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=63d417a8e9eef70044a768b6 #tryhackme via @tryhackme

    Post summary

    The post announces a walkthrough of the Follina CVE‑2022‑30190 exploitation on TryHackMe, indicating a PoC is available, but lacks detailed technical or tool-specific information.

    0002084
    1.3K followersView on X
  • CiberBaur@BotBauR
    Active Exploitation

    El vector de ataque principal de ChronusTeam ha sido a través de exploits de vulnerabilidades conocidas en software y sistemas operativos. En particular, han estado utilizando exploits para CVE-2022-30190 (Follina) y CVE-2022-37966 (Windows). También han estado utilizando herramientas de malware como el troyano AsyncRAT y el ransomware Conti. Según los registros de tráfico de red, han estado utilizando direcciones IP en Rusia y China para controlar sus operaciones. (3/6)

    Post summary

    ChronusTeam is actively exploiting CVE-2022-30190 (Follina) and CVE-2022-37966 in real-world attacks, using known vulnerabilities to compromise systems and employing IPs from Russia and China.

    1001044
    130 followersView on X
  • truemorgan@_truemorgan
    General

    Windows: CVE-2017-0144 CVE-2017-0145 CVE-2008-4250 CVE-2019-0708 CVE-2020-1472 CVE-2021-34527 CVE-2021-26855 CVE-2020-1350 CVE-2003-0352 CVE-2014-6324 CVE-2017-0199 CVE-2021-40444 CVE-2022-30190 CVE-2021-31166 CVE-2022-21907 CVE-2019-1182 CVE-2019-1181 CVE-2020-0601 CVE-2023-29363 CVE-2023-32014 CVE-2025-24985 CVE-2025-24993 CVE-2024-38063 CVE-2022-34718 CVE-2021-26857 CVE-2021-36934 CVE-2022-37969 CVE-2022-41033 CVE-2022-38028 CVE-2023-28252 CVE-2024-26169 CVE-2025-29824 CVE-2025-30400 CVE-2025-32701 CVE-2025-32706 CVE-2016-0099 CVE-2020-1048 CVE-2017-8529 CVE-2020-0688 CVE-2021-42287 CVE-2021-42278 CVE-2022-26923 CVE-2021-34523 CVE-2021-31207 CVE-2026-32202 CVE-2017-5754 CVE-2017-5753 CVE-2018-3639 CVE-2019-11135 CVE-2018-3620

    Post summary

    The provided text lists a series of Windows CVE identifiers without any additional context, technical details, or actionable information.

    10000106
    15 followersView on X
  • John Carter FBI Agent@djfofngfiiBebe
    General

    @scaredOfTheLarp @Percdye @duskangelz @realkimjihoon You are retarded bro. IOS Darksword exploit kit is another example. Also CVE-2022-30190. You can even go ahead and ask the most retarded AI if you can get hacked with a single click of a link and they would agree. Ask anybody is the cyber security community and they'll agree.

    Post summary

    A casual post that references the IOS Darksword exploit kit and mentions CVE-2022-30190, but provides no specifics or actionable information.

    1000085
    5 followersView on X
  • PeterSR@PeterSRWeb3
    Active Exploitation

    4/ Once opened, it chained the old Follina vuln (CVE-2022-30190) → dropped RATs + credential stealers + Defender exclusions. Not a http://Booking.com breach — pure brand impersonation + next-gen AI evasion.

    Post summary

    The message indicates that the old Follina vulnerability (CVE-2022-30190) is being actively exploited in the wild to drop RATs, steal credentials and exclude Defender, denoting real‑world attack activity.

    1000082
    1.4K followersView on X
  • 317ON13_LIRW@ToTo13ru_xakep
    General

    I just completed Follina MSDT room on TryHackMe! A walkthrough on the CVE-2022-30190, the MSDT service, exploitation of the service vulnerability, and consequent detection techniques and remediation processes https://tryhackme.com/room/follinamsdt?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=662fb6411f3680a87baf9e1f #tryhackme via @tryhackme

    Post summary

    The author completed a walkthrough of the Follina MSDT exploit (CVE-2022-30190), covering how the vulnerability is leveraged and outlining detection and remediation steps.

    0000024
CPE platform detail17 entries

17 of 17 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1507---
OSmicrosoftwindows_10_1607---
OSmicrosoftwindows_10_1809---
OSmicrosoftwindows_10_20h2---
OSmicrosoftwindows_10_21h1---
OSmicrosoftwindows_10_21h2---
OSmicrosoftwindows_11_21h2---
OSmicrosoftwindows_7---
OSmicrosoftwindows_8.1---
OSmicrosoftwindows_rt_8.1---
OSmicrosoftwindows_server_2008r2--
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_20h2---

Explore more