
Well that's one way to spearphish 😅 _____ CVE of the Week: DogWalk RCE in Windows MSDT (CVE-2022-34713) We know that legacy systems remain the quiet backbone of many organizations. That’s why we’ve focused our recent efforts on ensuring even your legacy environments are shielded against classic exploits like this critical path traversal flaw in the Windows Support Diagnostic Tool (MSDT) that allows attackers to bypass "Mark of the Web" protections and plant malicious files directly into a system's startup directory. Why it matters: - Attackers gain a permanent foothold with the user's privileges. - Exploited via crafted .diagcab files that often slip past basic email filters. Recommended actions: 1. Ensure the August 2022 (or later) cumulative updates are applied to all Windows and Server 2008/2012/2016/2019 instances. 2. For systems that cannot be patched, unregister the ms-msdt URL protocol handler to break the link between the browser and the vulnerable diagnostic tool. Use this mitigation script to apply the non-patch workaround: https://www.vicarius.io/vsociety/posts/cve-2022-34713-mitigation-script-dogwalk-path-traversal-vulnerability-in-the-windows-support-diagnostic-tool ^ This script serves as a critical stop-gap measure to harden your environment against CVE-2022-34713 when immediate patching is not feasible.
Post summary
The post explains CVE‑2022‑34713, a path‑traversal RCE in Windows MSDT, and urges admins to install August 2022 updates or use a provided mitigation script.
