
this is my simple article about CVE 2022-30190 (Follina) analysis. I use the lab from Letsdefend.

On May 27, 2022, the Nao_Sec technical team attempted to analyze and discovered a document in .doc format that appeared malicious. The document was indicated to have been uploaded from an IP address in Belarus. This suspicion was further traced and on May 30, 2022, precisely on Monday, Microsoft announced an indication of a Zero day named CVE- 2022- 30190.

It is known that the malicious file was indicated to refer to area code 0438 located in Italy, specifically the village of Follina. Thus Kevin Beamount, a researcher who was among the first to analyze this exploit, named it “follina”.