Skip to content
KitploitKITPLOIT
ツールブログ
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
MSDT_CVE-2022-30190 — このリポジトリは、Defenderの視点からFollina MSDTについて説明しています。 | Kitploit
ツール/GitHubGitHub/archanchoudhury/msdt_cve-2022-30190
侵害指標 (IOC) 管理脆弱性分析マルウェア分析脅威インテリジェンス学習と教育インシデントレスポンス
GitHubarchanchoudhury/msdt_cve-2022-30190

MSDT_CVE-2022-30190

このリポジトリは、Defenderの視点からFollina MSDTについて説明しています。

リポジトリを見る
37104年前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

MSDT_CVE-2022-30190

このリポジトリは、Defenderの視点からFollina MSDTについて解説しています。

目次

  • 概要
  • タイムライン
  • エクスプロイトの理解
  • IOCリスト
  • 検出戦略
  • テストと調査
  • 緩和策
  • 参照

概要

このバグは、Shadow Chaser Group の crazyman によって報告された、Microsoft Windows サポート診断ツール (MSDT) のリモートコード実行 (RCE) 脆弱性です。Microsoft は現在これを CVE-2022-30190 として追跡しています。この欠陥は、セキュリティ更新プログラムが提供されているすべての Windows バージョン (Windows 7 以降、Server 2008 以降) に影響します。

セキュリティ研究者 nao_sec が発見したように、これは脅威アクターが Word 文書を開いたりプレビューしたりする際に、MSDT を介して悪意のある PowerShell コマンドを実行するために使用されます。Redmond はこれを任意コード実行 (ACE) 攻撃と表現しています。

「この脆弱性の悪用に成功した攻撃者は、呼び出し元アプリケーションの権限で任意のコードを実行できます」と Microsoft は説明しています。

タイムライン

  • 2022年4月12日 — APTハンティンググループであるShadowchasing1のリーダーからMicrosoft MSRCへの最初の報告。この文書は、ロシアの就職面接をテーマにした、ロシアを標的とした実際のエクスプロイトです。
  • 2022年4月21日 — Microsoft MSRCは、セキュリティ関連の問題ではないとしてチケットをクローズしました(参考までに、マクロ無効でmsdtが実行されるのは問題です)。
  • 2022年5月?? — Microsoftは、Office 365 Insiderチャネルでこれを修正しようとしたか、偶然修正した可能性がありますが、CVEを文書化したり、どこかに書き留めたりしていません。その他の製品は脆弱なままです。
  • 2022年5月27日 — セキュリティベンダーNaoが、ベラルーシからアップロードされた文書をツイートしました。これも実際の攻撃です。
  • 2022年5月27日 — MSRCに再報告。
  • 2022年5月29日 — Andy Ful氏は、Office 365 Semi Annualチャネルに対しても依然として有効であり、オンプレミスのOfficeバージョンやEDR製品が検出に失敗していることから、これを公にゼロデイとして特定しました。

エクスプロイトの理解

  • このエクスプロイトの動作原理の詳細を理解するには、Huntressのブログこちらを参照してください。
  • エクスプロイトとその修復方法を理解するには、このビデオをご覧ください。

IOCリスト

  • 主要オブジェクト - 05-2022-0438.doc
    • sha256 4a24048f81afbe9fb62e7a6a49adbd1faf41f266b5f9feecdceb567aec096784
    • sha1 06727ffda60359236a8029e0b3e8a0fd11c23313
    • md5 52945af1def85b171870b31fa4782e52
  • ドロップされた実行可能ファイル
    • sha256 C:\Users\admin\AppData\Local\Temp\SDIAG_ecb8c0a2-7a1e-4b6c-8ae0-2245f03bcc15\DiagPackage.dll 3218488d62cb0858101d2ec63ec73a032bc9787f5f87cb46abbea4477c97b16f
    • sha256 C:\Users\admin\AppData\Local\Temp\SDIAG_ecb8c0a2-7a1e-4b6c-8ae0-2245f03bcc15\en-US\DiagPackage.dll.mui c6d837ec0850e22c83b400fcded1791a2f4f99f0c56d6fc7d93e92a8b72c098d
    • sha256 C:\Users\admin\AppData\Local\Temp\r5qxr4ie.dll aa967ae9f6d80bdbd0f315defa17aaee0e756e7e2ad0e5261d8254bc0af1cc02
    • sha256 C:\Users\admin\AppData\Local\Temp\t52wyhbe.dll daf716cbe8810085251e6ef1e39869a9e61d929fac12ea5684c3b2caf993666b
    • sha256 C:\Users\admin\AppData\Local\Temp\qtwoghs1.dll f5361b6c9db8ac25433ae21f9a7b6490cc372ce2b1f802e2b06d5b904ce97109
  • DNSリクエスト
    • domain www[.]xmlformats[.]com
  • 接続先
    • ip 141.105.65.149
    • ip 20.42.65.85
    • ip 13.107.42.16
  • HTTP/HTTPSリクエスト
    • url hxxps://www[.]xmlformats[.]com/office/word/2022/wordprocessingDrawing/
    • url hxxps://www[.]xmlformats[.]com/office/word/2022/
    • url hxxps://www[.]xmlformats[.]com/office/word/2022/wordprocessingDrawing/RDF842l[.]html

検出戦略

  • スレットハンティングを行うには、Sigmaルールをこちらで見つけることができます。

  • 以下は、さらにチューニング可能な検出ルールです。Bala Ganesh氏に感謝します。全文はこちらで読めます。

  • MS Defender:

root@kitploit:~
DeviceProcessEvents | where ((ProcessCommandLine contains "WINWORD.EXE") and (ProcessCommandLine contains "msdt.exe") and (ProcessCommandLine contains "sdiagnhost.exe" or ProcessCommandLine contains "csc.exe" or ProcessCommandLine contains "PCWDiagnostic" or ProcessCommandLine contains "IT_ReBrowserForFile" or ProcessCommandLine contains "IT_BrowserForFile" or ProcessCommandLine contains "conhost.exe"))
  • Splunk:
root@kitploit:~
[Doc Malware]
alert.severity = 2
description = Detection (Rule ID: 74566a6a66aaasdq2ed)
cron_schedule = 0 * * * *
disabled = 1
is_scheduled = 1
is_visible = 1
dispatch.earliest_time = -60m@m
dispatch.latest_time = now
search = (source="WinEventLog:*" AND (CommandLine="*WINWORD.EXE*") AND (CommandLine="*msdt.exe*") AND (CommandLine="*sdiagnhost.exe*" OR CommandLine="*csc.exe*" OR CommandLine="*PCWDiagnostic*" OR CommandLine="*IT_ReBrowserForFile*" OR CommandLine="*IT_BrowserForFile*" OR CommandLine="*conhost.exe*"))
alert.suppress = 0
alert.track = 1
  • Qradar:
root@kitploit:~
SELECT UTF8(payload) from events where LOGSOURCETYPENAME(devicetype)='Microsoft Windows Security Event Log' and ("Process CommandLine" ilike '%WINWORD.EXE%') and ("Process CommandLine" ilike '%msdt.exe%') and ("Process CommandLine" ilike '%sdiagnhost.exe%' or "Process CommandLine" ilike '%csc.exe%' or "Process CommandLine" ilike '%PCWDiagnostic%' or "Process CommandLine" ilike '%IT_ReBrowserForFile%' or "Process CommandLine" ilike '%IT_BrowserForFile%' or "Process CommandLine" ilike '%conhost.exe%')
  • GrayLog
root@kitploit:~
(CommandLine.keyword:*WINWORD.EXE* AND CommandLine.keyword:*msdt.exe* AND CommandLine.keyword:(*sdiagnhost.exe* *csc.exe* *PCWDiagnostic* *IT_ReBrowserForFile* *IT_BrowserForFile* *conhost.exe*))
Sumologic
(_sourceCategory=*windows* AND (CommandLine = "*WINWORD.EXE*") AND (CommandLine = "*msdt.exe*") AND (CommandLine = "*sdiagnhost.exe*" OR CommandLine = "*csc.exe*" OR CommandLine = "*PCWDiagnostic*" OR CommandLine = "*IT_ReBrowserForFile*" OR CommandLine = "*IT_BrowserForFile*" OR CommandLine = "*conhost.exe*"))
  • Elastic KQL:
root@kitploit:~
(process.command_line:*WINWORD.EXE* AND process.command_line:*msdt.exe* AND process.command_line:(*sdiagnhost.exe* OR *csc.exe* OR *PCWDiagnostic* OR *IT_ReBrowserForFile* OR *IT_BrowserForFile* OR *conhost.exe*))

Brent Murphy氏がこちらで説明している以下のクエリも適用できます。

root@kitploit:~
process where event.type in ("start" , "process_created") and (process.pe.original_file_name : "msdt.exe" or process.name : "msdt.exe") and (process.parent.pe.original_file_name : ("winword.exe", "excel.exe", "outlook.exe", "powerpnt.exe") or process.parent.name : ("winword.exe", "excel.exe", "outlook.exe", "powerpnt.exe"))
  • Cortex XDRでXQL Searchを使用してこの攻撃をハンティングできます。詳細はこちら
root@kitploit:~
# office processes spawning msdt.exe

config case_sensitive = false timeframe = 30d
| dataset = xdr_data
| filter event_type = ENUM.PROCESS and action_process_image_command_line contains "msdt.exe" and actor_process_image_name in ("winword.exe", "powerpnt.exe", "excel.exe", "msaccess.exe","visio.exe","onenote.exe","powershell.exe")
| fields agent_hostname , action_process_image_command_line , action_process_image_path , actor_process_command_line , actor_process_image_path , causality_actor_process_image_path

# msdt.exe execution with suspicious argument

config case_sensitive = false timeframe = 30d
| dataset = xdr_data
| filter event_type = ENUM.PROCESS and action_process_image_command_line contains "msdt.exe" and
action_process_image_command_line contains "it_browseforfile"
| fields agent_hostname , action_process_image_command_line , action_process_image_path , actor_process_command_line , actor_process_image_path , causality_actor_process_image_path
  • この挙動のハンティングに加えて、レジストリキー HKEY_USERS*SID\SOFTWARE\Microsoft\Office\16.0\Common\Internet\Server Cache* を大規模にクエリし、結果を分析することも有用です。詳細はこちらの投稿を参照してください。
  • Velociraptorは、悪意のあるOffice文書から可能性のあるC2 URLを特定するために、Return Office Internet Server Cacheレジストリキーと値を識別する検出ロジックをこちらに作成しました。
  • Joe Securityが開発したYARAルールはこちらにあります。
  • Crowdstrikeのクエリは以下のように実行できます。
root@kitploit:~
index=main (ProcessRollup2 OR SyntheticProcessRollup2 OR ProcessBlocked*) ParentBaseFileName IN ("OUTLOOK.EXE","WINWORD.EXE","EXCEL.EXE") CommandLine="*msdt.exe*"
| table ComputerName ParentBaseFileName CommandLine FileName
  • %localappdata%\Diagnostics と %localappdata%\ElevatedDiagnostics (昇格インスタンスの場合) 内の "PCW.debugreport.xml" ファイルは、実行時に生成され、ペイロードを含んでいます。こちらで確認してください。
  • 現在の概念実証 (PoC) の反復では、Microsoft Officeアプリケーションから msdt.exe を呼び出します。Crowdstrike Falcon用の一般化されたハンティングクエリはこちらにあります。
root@kitploit:~
index=main sourcetype=ProcessRollup* event_simpleName=ProcessRollup2
| search ParentBaseFileName IN (winword.exe, excel.exe, powerpnt.exe, outlook.exe) 
| search FileName=msdt.exe
| table _time, aid, ComputerName, UserName, UserSid_readable, ParentBaseFileName, FileName, CommandLine
| lookup local=true aid_master aid OUTPUT AgentVersion, Version, MachineDomain, OU, SiteName
  • 環境内での通常のmsdt.exeの使用状況をさらにプロファイリングしてベースライン化するには、Crowdstrike Falconで以下のクエリを使用できます。
root@kitploit:~
index=main sourcetype=ProcessRollup* event_simpleName=ProcessRollup2
| search FileName=msdt.exe
| eval FileName=lower(FileName)
| eval ParentBaseFileName=lower(ParentBaseFileName)
| stats dc(aid) as endpointCount, count(aid) as executionCount by FileName, ParentBaseFileName
| sort -executionCount
  • Elastic SecurityチームはSIEM用の既存ルールを更新し、lolbinとしてのmsdt.exeに対する新しいルールを追加しました。検出ルール1とルール2を確認してください。
  • MS Sentinelを使用している場合は、以下を使用できます。
root@kitploit:~
#Detects the exploitation of Follina Microsoft Code Execution vulnerability

SecurityEvent 
| where EventID==4688 
| where ParentProcessName has_any ('winword.exe','excel.exe','outlook.exe') 
| where NewProcessName contains "msdt.exe" or CommandLine contains "msdt.exe"
| project TimeGenerated, NewProcessId, NewProcessName, ParentProcessName, CommandLine, EventID, Activity, Computer

#The below query could return false-positives please verify the output and modify the query according to your environment.

SecurityEvent 
| where EventID==4688 
| where ParentProcessName has_any ('sdiagnhost.exe', 'msdt.exe')
//| where NewProcessName contains "powershell" or NewProcessname contains "cmd.exe"  //optional: you can include this line for directly finding powershell or cmd process spawns
| project TimeGenerated, NewProcessId, NewProcessName, ParentProcessName, CommandLine, EventID, Activity, Computer

テストと調査

⚠⚠以下は研究および学習目的のみに使用してください

  • 添付のサンプルを活用してください
  • John Hammond氏が作成した素晴らしいコードとプラットフォームを活用してください こちら
  • 兵器化されたCVE-2021-40444はこちらにあります
  • Cas van Cooten氏が作成したこのPOCを活用してください こちら

緩和策

  • Microsoftから公式の対応が発表されるまで、ms-msdtのプロトコルハンドラーを削除することが最も安全な緩和策と考えられます。この方法は大企業ではテストしていないため、プロトコルハンドラーを広く無効にすることによる二次的な影響が生じる可能性があります。しかし、悪用に成功した場合の影響(任意のコード実行)を考慮すると、これは合理的なリスクベースのアプローチのように思われます(少なくともOffice文書を開くシステムでは)。プロトコルハンドラーの削除は、管理者コマンドプロンプトで以下のコマンドを実行するだけです。
root@kitploit:~
reg delete HKEY_CLASSES_ROOT\ms-msdt /f

***このキーの内容を削除する前にバックアップし、パッチが利用可能になったらレジストリにマージできるようにしてください。

  • 以下のPSスクリプトを使用して、レジストリの変更を行うことができます。Kelvin Tegelaarに感謝します。
root@kitploit:~
$ENV:ActivateWorkaround = "Yes"
if($ENV:ActivateWorkaround -eq "Yes") {
    New-PSDrive -PSProvider registry -Root HKEY_CLASSES_ROOT -Name HKCR
    Set-Item -Path "HKCR:\ms-msdt" -Value "URL:ms-msdt_bak"
    Rename-Item -Path "HKCR:\ms-msdt" -newName "ms-msdt_bak"
} else {
    New-PSDrive -PSProvider registry -Root HKEY_CLASSES_ROOT -Name HKCR
    Rename-Item -Path "HKCR:\ms-msdt_bak" -newName "ms-msdt"

    Set-Item -Path "HKCR:\ms-msdt" -Value "URL:ms-msdt"
}

  • ユーザーに、添付ファイルを含むメールは常に報告し、開かないように教育してください。この脆弱性は、ホバーするだけでも悪用される可能性があります。そのため、エンドユーザーは細心の注意を払う必要があります。
  • 環境でMicrosoft Defenderの攻撃表面の減少(ASR)ルールを利用している場合、「すべてのOfficeアプリケーションが子プロセスを作成しないようにする」ルールをブロックモードで有効にすると、この悪用を防ぐことができます。ただし、まだASRを使用していない場合は、まず監査モードでルールを実行し、エンドユーザーへの悪影響がないことを確認するために結果を監視することをお勧めします。

参照

  • https://thehackernews.com/2022/05/watch-out-researchers-spot-new.html
  • https://reaqta.com/2022/05/threat-analysis-msdt-exploit-with-maldocs/
  • https://www.joesandbox.com/analysis/636202/0/html
  • https://www.bleepingcomputer.com/news/microsoft/microsoft-shares-mitigation-for-office-zero-day-exploited-in-attacks/
  • https://nakedsecurity.sophos.com/2022/05/31/mysterious-follina-zero-day-hole-in-office-what-to-do/
  • https://www.theregister.com/2022/05/30/follina_microsoft_office_vulnerability/
  • https://msrc-blog.microsoft.com/2022/05/30/guidance-for-cve-2022-30190-microsoft-support-diagnostic-tool-vulnerability/
  • https://unit42.paloaltonetworks.com/cve-2022-30190-msdt-code-execution-vulnerability/
ツールをダウンロード