🔒 Closed What do you think of this "MS WORD" expoit? (Can it pwn you, or Run RCE?)

Status
Not open for further replies.
This is the recently discovered follina exploit which is assigned as CVE-2022-30190. it allows the attacker to get a Remote Code
Execution (RCE) on your computer. in-order to trigger this exploit, the user need not even open the maldoc, he/she just needs to preview it!
the vulnerability lies in the ms-msdt url protocol -windows blindly executes code when this protocol is used along with some parameters and a Powershell E×ρréššion.

It can run Malicious commands and HΔck/Delete your files. And it can even Spam RICKROLL

I have tried writing a script of an exploit myself and it was powerful, i hope you guys be aware of opening and downloading DOCX. file and clicking Buttons :> .


I have prepared some of the workaround fix to avoid this kind of attack.


  • At first open your CMD & Run as Administrator
  • Execute this command to Backup your Registry reg export HKEY_CLASSES_ROOT\ms-msdt backup
  • Now disable the MSDT Protocol reg delete HKEY_CLASSES_ROOT\ms-msdt /f
  • Done.


Keep Save bros. And i'm hoping you to be well aware of this. :>
 
let google docs open the file
Prolly not a good idea..

Why?
because it uses a MSDT URL protocol, if you open or even preview it. The payload will execute. thats why i mentioned POWERFUL.
It can be also exploited using javascript for executing the payload and run secretly without your consent or even gawing palaman sa mga Software.
(The exploit only works on Windows 7 and up)
 
Prolly not a good idea..

Why?
because it uses a MSDT URL protocol, if you open or even preview it. The payload will execute. thats why i mentioned POWERFUL.
It can be also exploited using javascript for executing the payload and run secretly without your consent or even gawing palaman sa mga Software.
(The exploit only works on Windows 7 and up)
si google na nga ang nag open kasi wala akong naka install na office sa PC ko, kaya ba niya i-häçk si google?
 
si google na nga ang nag open kasi wala akong naka install na office sa PC ko, kaya ba niya i-häçk si google?
I mean yung file mismo nag eexecute ng payload which is the MSDT URI scheme...
(BUT idk if google docs allowing something to execute a URI in their reader, yan lang sa pagkakaalam ko, pero its up to you.)

Basta if kung galing sa non-trusted sites yung file or nakareceive ka ng random email na may (.docx) file wag mong nalang buksan. :>
 
Status
Not open for further replies.

About this Thread

  • 10
    Replies
  • 660
    Views
  • 5
    Participants
Last reply from:
PHC-TheGlock

Trending Topics

Online now

Members online
1,313
Guests online
2,862
Total visitors
4,175

Forum statistics

Threads
2,319,826
Posts
29,202,766
Members
1,179,979
Latest member
ralph27
Back
Top