Skip to the content
  • Why Vertex
    • Expertise in Education
    • Your Trusted Partner
    • Humanitix Case Study
    • Give Back
    • Careers
  • Penetration Testing
  • ISO27001
  • Cyber Training
  • Solutions
    • Cyber Security Audit
    • Incident Response
    • Managed Services
  • News
  • Contact
  • Why Vertex
    • Expertise in Education
    • Your Trusted Partner
    • Humanitix Case Study
    • Give Back
    • Careers
  • Penetration Testing
  • ISO27001
  • Cyber Training
  • Solutions
    • Cyber Security Audit
    • Incident Response
    • Managed Services
  • News
  • Contact
LOG IN

Zero Day Microsoft Office Remote Code Execution

There is a zero day (CVE-2022-30190 Follina) with Microsoft Office, which with an appropriately crafted MS office document such as word or excel (and the rest) will allow a remote attacked to gain access to your computer. It uses an inbuilt MS support URL to execute commands.

It looks like there will be some time before this security bug is fixed, so to avoid being attacked there are some immediate things you should consider doing:

  1. Make sure you email service will attempt to find these email attachments and block them
  2. If you have a good AV it should detect and block this.
  3. Hardening steps (where possible) to block executables spawned from office programs.
  4. Hardening steps (where possible) to block network access for office programs.
  5. Users have been trained to preview suspicious files in gmail before downloading to confirm it is actually needed.
  6. Patch security vulnerability as soon as available
  7. Block / Quarantine all email with office attachments until the patch is available
  8. Remove the use of URL protocol “ms-msdt:” by deleting HKEY_CLASSES_ROOT\ms-msdt

Reach out to us if you need any assistance applying these or other protections.

CATEGORIES

Cyber Attack - Cyber Security - Hacker

TAGS

SHARE

PrevPreviousACSC Issues Advisory to Enhance Security Posture
NextRSA Conference 2022Next

Follow Us!

Facebook Twitter Linkedin Instagram
Cyber Security by Vertex, Sydney Australia

Your partner in Cyber Security.

Terms of Use | Privacy Policy

Accreditations & Certifications

blank
blank
blank
blank
blank
  • 1300 229 237
  • Suite 13.04 189 Kent Street Sydney NSW 2000 Australia
  • 121 King St, Melbourne VIC 3000
  • Lot Fourteen, North Terrace, Adelaide SA 5000
  • Level 2/315 Brunswick St, Fortitude Valley QLD 4006, Adelaide SA 5000

(c) 2025 Vertex Technologies Pty Ltd.

download (2)
download (4)

We acknowledge Aboriginal and Torres Strait Islander peoples as the traditional custodians of this land and pay our respects to their Ancestors and Elders, past, present and future. We acknowledge and respect the continuing culture of the Gadigal people of the Eora nation and their unique cultural and spiritual relationships to the land, waters and seas.

We acknowledge that sovereignty of this land was never ceded. Always was, always will be Aboriginal land.