Microsoft patches the Follina Windows zero-day, which let hackers execute malicious PowerShell commands and had been exploited by state-backed actors
Microsoft has released security updates with the June 2022 cumulative Windows Updates to address a critical Windows zero-day vulnerability known …
Context & Ripple Effects
The flaw had been reported to Microsoft in April and was described as critical while still unpatched in late May; the June update closes that exposed interval after an RCE exploit was reported active in the wild. It also follows a history in which a prior Windows zero-day patch did not fully resolve the vulnerability, making remediation quality as important as release speed.
First-order effects
- Windows users and administrators can deploy the June cumulative updates to remove the Follina route used to launch malicious PowerShell commands.
- State-backed actors exploiting Follina lose a known Windows execution path on systems that receive the update.
Second-order effects
- Enterprise security teams must prioritize update deployment and verify coverage, since an earlier Microsoft zero-day fix required adjustments before the underlying issue was resolved.
- Attackers relying on PowerShell-based execution must shift toward other unpatched access or execution techniques against updated Windows estates.
Third-order effects
- Repeated Windows zero-day disclosures and incomplete-fix episodes push vulnerability response toward faster patch adoption paired with validation, rather than treating Patch Tuesday deployment as sufficient proof of remediation.
The trend: Windows security operations are becoming a continuous contest between actively exploited flaws, vendor patch cadence, and customers' ability to validate fixes quickly.