On 27 May 2022 researchers publicised a malicious Word document exploiting a previously unknown code-execution flaw, subsequently tracked as CVE-2022-30190 and named Follina. The vulnerability was in the Microsoft Support Diagnostic Tool, a component present across Windows versions including server editions.
The technique referenced an external resource that invoked the ms-msdt URL protocol handler to run code. Reporting states it worked with macros disabled and with the document opened in Protected View. Analysts reported the flaw had been submitted to Microsoft on 12 April 2022, with in-the-wild documents observed at that time.
The Advice Was Wrong, Not Ignored
Every user in every organisation had been told the same thing for ten years: documents are dangerous when you enable macros, so do not enable macros. That instruction was correct, widely taught, and completely irrelevant here.
This corpus is generally sceptical of security awareness training as a control, and 22-0808 records why — three Cloudflare employees clicked and the outcome was decided by the factor, not the click. Follina is the same argument from the other side. A person who had followed the guidance perfectly was still exploited, because the guidance described one mechanism and the attack used another.
A Diagnostic Tool Is Reachable From A Document
The interesting property is not the memory-safety detail; it is the reachability. A troubleshooting utility, present on every Windows install and intended to gather system information for support, could be invoked by a file arriving in email.
We have recorded the same class of surprise at 25-0723 and 26-0714b, where machine keys turned out to be reachable and durable, and at 22-0922, where an endpoint answered anyone. Attack surface is not what a component does; it is who can make it do it.
Six Weeks Between Report And Publicity
Reporting places submission to the vendor on 12 April and public awareness on 27 May, with malicious documents already circulating at the point of submission.
The desk records the interval without adjudicating it. What matters for this database is that during it the flaw was being exploited and defenders did not know the mechanism, which is the same asymmetry filed at 23-0518 and 25-0719 — the difference between when a thing is known and when it is known to the people who have to act on it.
Built on vendor and researcher analyses of CVE-2022-30190. The 27 May 2022 publicity, the identification of the Microsoft Support Diagnostic Tool, the ms-msdt protocol handler technique, and the reports that exploitation succeeded with macros disabled and in Protected View are as documented by multiple analysts. The 12 April 2022 submission date and the account of in-the-wild documents at that time are as reported and this desk has not independently established them. No proof-of-concept, payload or indicator is reproduced. CVSS figures quoted at the time varied by source and none is carried here. Graded high. Corrections: corrections@forensicpost.com.