Desk live·
ForensicPost
Cloud/Exploitation/File 22-0527

Follina Exploited Word Documents With No Macro and No Protected View Warning

Follina reached a Windows diagnostic tool through a Word document by way of a URL protocol handler. A decade of user advice had been "do not enable macros", and this needed none.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetWindows users
ActorUnattributed
D. Kennedy11 min readConfidence: high2 sources reviewed

On 27 May 2022 researchers publicised a malicious Word document exploiting a previously unknown code-execution flaw, subsequently tracked as CVE-2022-30190 and named Follina. The vulnerability was in the Microsoft Support Diagnostic Tool, a component present across Windows versions including server editions.

The technique referenced an external resource that invoked the ms-msdt URL protocol handler to run code. Reporting states it worked with macros disabled and with the document opened in Protected View. Analysts reported the flaw had been submitted to Microsoft on 12 April 2022, with in-the-wild documents observed at that time.

The Advice Was Wrong, Not Ignored

Every user in every organisation had been told the same thing for ten years: documents are dangerous when you enable macros, so do not enable macros. That instruction was correct, widely taught, and completely irrelevant here.

This corpus is generally sceptical of security awareness training as a control, and 22-0808 records why — three Cloudflare employees clicked and the outcome was decided by the factor, not the click. Follina is the same argument from the other side. A person who had followed the guidance perfectly was still exploited, because the guidance described one mechanism and the attack used another.

A Diagnostic Tool Is Reachable From A Document

The interesting property is not the memory-safety detail; it is the reachability. A troubleshooting utility, present on every Windows install and intended to gather system information for support, could be invoked by a file arriving in email.

We have recorded the same class of surprise at 25-0723 and 26-0714b, where machine keys turned out to be reachable and durable, and at 22-0922, where an endpoint answered anyone. Attack surface is not what a component does; it is who can make it do it.

Six Weeks Between Report And Publicity

Reporting places submission to the vendor on 12 April and public awareness on 27 May, with malicious documents already circulating at the point of submission.

The desk records the interval without adjudicating it. What matters for this database is that during it the flaw was being exploited and defenders did not know the mechanism, which is the same asymmetry filed at 23-0518 and 25-0719 — the difference between when a thing is known and when it is known to the people who have to act on it.

How we reported this

Built on vendor and researcher analyses of CVE-2022-30190. The 27 May 2022 publicity, the identification of the Microsoft Support Diagnostic Tool, the ms-msdt protocol handler technique, and the reports that exploitation succeeded with macros disabled and in Protected View are as documented by multiple analysts. The 12 April 2022 submission date and the account of in-the-wild documents at that time are as reported and this desk has not independently established them. No proof-of-concept, payload or indicator is reproduced. CVSS figures quoted at the time varied by source and none is carried here. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. CVE-2022-30190: Microsoft Support Diagnostic Tool (MSDT) RCE Vulnerability "Follina"Fortinet FortiGuard Labs
  2. Detect the Follina MSDT vulnerability (CVE-2022-30190)Qualys
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary