NOMISEC-WesyHub/CVE-2022-30190---Follina---Poc-Exploit

NOMISEC WORKING POC
Exploit for CVE-2022-30190 - Microsoft Office Word MSDTJS
AI Analysis

This is a functional PoC exploit for CVE-2022-30190 (Follina), which leverages a malicious Office document to execute arbitrary commands via the MSDT URL protocol handler. The script generates a weaponized document and hosts a payload server to trigger the vulnerability.

Attack Type
RCE
Complexity
moderate
Reliability
reliable
MITRE ATT&CK
T1204.002 - Malicious File T1195.002 - Compromise Software Supply Chain
Loading exploit code...
Download ZIP Password: eip
Source
Platform Nomisec
Type poc
Files 17
Stars 0
Forks 1
Last Push Jun 03, 2022
Authors
WesyHub
Vulnerability
CVE-2022-30190
Microsoft Office Word MSDTJS
HIGH KEV
CVSS 7.8