PHC-TheGlock
Elite
This is the recently discovered follina exploit which is assigned as CVE-2022-30190. it allows the attacker to get a Remote Code
Execution (RCE) on your computer. in-order to trigger this exploit, the user need not even open the maldoc, he/she just needs to preview it!
the vulnerability lies in the ms-msdt url protocol -windows blindly executes code when this protocol is used along with some parameters and a Powershell E×ρréššion.
It can run Malicious commands and HΔck/Delete your files. And it can even Spam RICKROLL
I have tried writing a script of an exploit myself and it was powerful, i hope you guys be aware of opening and downloading DOCX. file and clicking Buttons :> .
I have prepared some of the workaround fix to avoid this kind of attack.
Keep Save bros. And i'm hoping you to be well aware of this. :>
Execution (RCE) on your computer. in-order to trigger this exploit, the user need not even open the maldoc, he/she just needs to preview it!
the vulnerability lies in the ms-msdt url protocol -windows blindly executes code when this protocol is used along with some parameters and a Powershell E×ρréššion.
It can run Malicious commands and HΔck/Delete your files. And it can even Spam RICKROLL
I have tried writing a script of an exploit myself and it was powerful, i hope you guys be aware of opening and downloading DOCX. file and clicking Buttons :> .
I have prepared some of the workaround fix to avoid this kind of attack.
- At first open your CMD & Run as Administrator
- Execute this command to Backup your Registry
reg export HKEY_CLASSES_ROOT\ms-msdt backup - Now disable the MSDT Protocol
reg delete HKEY_CLASSES_ROOT\ms-msdt /f - Done.
Keep Save bros. And i'm hoping you to be well aware of this. :>

