Researchers told Microsoft on April 12 about an RCE Windows exploit active in the wild; Microsoft called the flaw critical on May 30 but still hasn't patched it
0 click — 0 day — in a core windows application — hard to detect The requirements are fairly specific, but they occur often enough to make CVE-2022-30190 the ideal means to detonate payloads on Windows machines. https://twitter.com/... @bleepincomputer : @serghei CISA urges admins and users to apply workarounds for this actively exploited zero-day (CVE-2022-30190 aka Follina) in the Windows Microsoft Support Diagnostic Tool (MSDT). https://www.cisa.gov/... https://twitter.com/...
Context & Ripple Effects
Microsoft had previously issued fixes for an actively exploited Internet Explorer RCE, making the unpatched MSDT issue part of a recurring Windows zero-day response cycle. Here, however, CISA is directing administrators toward mitigations before a vendor fix is available.
The immediate episode was later closed by Microsoft's Follina patch, underscoring that the gap between disclosure, public exploitation, and a shipped update was the operational problem for Windows defenders.
First-order effects
- Windows administrators must apply CISA's recommended workarounds to reduce exposure to CVE-2022-30190 in MSDT while Microsoft has no patch available.
- Microsoft faces an urgent remediation obligation after designating Follina critical while attackers are already exploiting it.
Second-order effects
- Organizations that depend on Windows endpoints must treat compensating controls as part of incident response, rather than waiting for Microsoft's normal patch delivery.
- CISA's intervention increases pressure on Microsoft to pair vulnerability severity labels with deployable mitigations when an actively exploited flaw affects a core component.
Third-order effects
- Repeated actively exploited Windows flaws, including the later DogWalk warning and patch, point toward endpoint security operations relying more on rapid workarounds alongside vendor updates.
- The pattern shifts scrutiny from whether a vulnerability is eventually fixed to how quickly Microsoft, CISA, and enterprise administrators can contain exploitation during the disclosure-to-patch interval.
The trend: Windows zero-day defense is becoming a coordinated race between vendor patching and administrator-deployed mitigations for flaws already under active exploitation.