Netskope Threat Labs

CVE-2022-30190

ATP Sandbox Adv. HeuristicsAVNetskope IPS

CVE-2022-30190 (Follina) is a remote code execution vulnerability in the Microsoft Windows Support Diagnostic Tool that cyberattackers exploit via malicious Office documents to execute arbitrary code without user interaction. A crafted document triggers an external protocol call that hands execution to a malicious script, bypassing macros entirely. Its reliability and simplicity made it one of the most abused Office flaws of recent years across criminal and state sponsored campaigns.

First seen
June 2022
Last seen
October 2026
Alert Name
DeepScan:Generic.Exploit.CVE-2022-30190.B.FFFFFFFE
DeepScan:Generic.Exploit.CVE-2022-30190.I.FFFFFFFE
Document-HTML.Exploit.CVE-2022-30190
Document-Office.Exploit.CVE-2022-30190
Document-Word.Exploit.CVE-2022-30190
Document-XML.Exploit.CVE-2022-30190
Dump:Generic.Exploit.CVE-2022-30190.B.FFFFFFFE
Dump:Generic.Exploit.CVE-2022-30190.I.FFFFFFFE
Exploit.CVE-2022-30190.Gen.1
Exploit.CVE-2022-30190.Gen.1:0E2E2