/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researchers told Microsoft on April 12 about an RCE Windows exploit active in the wild; Microsoft called the flaw critical on May 30 but still hasn't patched it

0 click — 0 day — in a core windows application — hard to detect The requirements are fairly specific, but they occur often enough to make CVE-2022-30190 the ideal means to detonate payloads on Windows machines. https://twitter.com/... @bleepincomputer : @serghei CISA urges admins and users to apply workarounds for this actively exploited zero-day (CVE-2022-30190 aka Follina) in the Windows Microsoft Support Diagnostic Tool (MSDT). https://www.cisa.gov/... https://twitter.com/...

Ars Technica Dan Goodin

Context & Ripple Effects

Microsoft had previously issued fixes for an actively exploited Internet Explorer RCE, making the unpatched MSDT issue part of a recurring Windows zero-day response cycle. Here, however, CISA is directing administrators toward mitigations before a vendor fix is available.

The immediate episode was later closed by Microsoft's Follina patch, underscoring that the gap between disclosure, public exploitation, and a shipped update was the operational problem for Windows defenders.

First-order effects

  • Windows administrators must apply CISA's recommended workarounds to reduce exposure to CVE-2022-30190 in MSDT while Microsoft has no patch available.
  • Microsoft faces an urgent remediation obligation after designating Follina critical while attackers are already exploiting it.

Second-order effects

  • Organizations that depend on Windows endpoints must treat compensating controls as part of incident response, rather than waiting for Microsoft's normal patch delivery.
  • CISA's intervention increases pressure on Microsoft to pair vulnerability severity labels with deployable mitigations when an actively exploited flaw affects a core component.

Third-order effects

  • Repeated actively exploited Windows flaws, including the later DogWalk warning and patch, point toward endpoint security operations relying more on rapid workarounds alongside vendor updates.
  • The pattern shifts scrutiny from whether a vulnerability is eventually fixed to how quickly Microsoft, CISA, and enterprise administrators can contain exploitation during the disclosure-to-patch interval.

The trend: Windows zero-day defense is becoming a coordinated race between vendor patching and administrator-deployed mitigations for flaws already under active exploitation.

Discussion

  • @gossithedog Kevin Beaumont on x
    Microsoft have assigned CVE-2022-30190 to this. The blog references how Protected Mode “prevents” the attack which is... well.. yeah. They don't reference it as zero day and haven't lit it up as a zero day in MS Threat and Vulnerability Management. https://msrc-blog.microsoft.com…
  • @bleepincomputer @bleepincomputer on x
    @serghei CISA urges admins and users to apply workarounds for this actively exploited zero-day (CVE-2022-30190 aka Follina) in the Windows Microsoft Support Diagnostic Tool (MSDT). https://www.cisa.gov/... https://twitter.com/...
  • @dangoodin001 Dan Goodin on x
    This is every bit as bad as it sounds, only worse. — 0 click — 0 day — in a core windows application — hard to detect The requirements are fairly specific, but they occur often enough to make CVE-2022-30190 the ideal means to detonate payloads on Windows machines. https://twitter…
  • @aspi_icpc @aspi_icpc on x
    2⃣ 'Chinese-linked threat actors are now actively exploiting a Microsoft Office zero-day vulnerability (known as 'Follina') to execute malicious code remotely on Windows systems.' | Read the @BleepinComputer article here ⬇️ https://www.bleepingcomputer.com/ ...
  • @extremelabs Tom Henderson on x
    Oh Crap: https://arstechnica.com/... Just tried it, and yep, works like a charm. Look for emergency patches shortly. Good work, @dangoodin001