
All about CVE-2022-30190, aka follina, that is a RCE vulnerability that affects Microsoft Support Diagnostic Tools (MSDT) on Office apps such as Word. This is a very simple POC, feel free to check the sources below for more threat intelligence.
CVE-2022-30190, 일명 follina에 관한 모든 것입니다. 이는 Word와 같은 Office 앱에서 Microsoft Support Diagnostic Tools(MSDT)에 영향을 미치는 RCE 취약점입니다. 이는 매우 간단한 POC이며, 더 많은 위협 인텔리전스를 위해 아래 출처를 확인하시기 바랍니다.
usage: follina.py [-h] [--command COMMAND] [--ip IP] [--port PORT] [--output OUTPUT] [--reverse REVERSE]
POC for CVE-2022-30190, aka follina
options:
-h, --help show this help message and exit
--command COMMAND, -c COMMAND
The command to run on the victim (defaults to calc.exe)
--ip IP, -i IP IP to serve the payload on (defaults to 127.0.0.1)
--port PORT, -p PORT Port to serve the payload on (defaults to 4444)
--output OUTPUT, -o OUTPUT
Filename for output, should end with extension .doc, .docx or maybe .rtf (defaults to maldoc.docx)
--reverse REVERSE, -r REVERSE
Instantiate a reverse shell connection from the target at port furnished. 64-bits systems only.
레지스트리에서 MSDT를 비활성화하면 이 문제가 해결됩니다.
reg delete HKEY_CLASSES_ROOT\ms-msdt /f
https://0xsp.com/offensive/follina-cve-2022-30190-rtf/
https://github.com/JMousqueton/PoC-CVE-2022-30190