MSDT Follina Execution
Abusing the ms-msdt: URI protocol handler (CVE-2022-30190, 'Follina') to run arbitrary commands from an Office document without needing macros.
Follina (CVE-2022-30190) abuses the ms-msdt: URI protocol handler,
registered by the Microsoft Support Diagnostic Tool, to run arbitrary
commands. The distinctive part of this technique is not the payload delivery
mechanism — it is that Word can be made to invoke the handler through a
document's remote-template feature (word/_rels/document.xml.rels pointing
at an external HTML file) without the document containing a macro and
without Protected View blocking it, since the template fetch happens before
any macro-security prompt would apply.
msdt.exe itself is a signed, ordinary Windows diagnostics tool; the
vulnerability is in how the protocol handler passes its parameters to it.
How it works
The HTML fetched via the remote template contains a script that navigates to
an ms-msdt: URI carrying an encoded diagnostic parameter, which in turn
smuggles a PowerShell command:
ms-msdt:/id PCWDiagnostic /skip force /param "IT_RebrowseForFile=cal?c IT_LaunchMethod=ContextMenu IT_SelectProgram=NotListed IT_BrowseForFile=$(Invoke-Expression($(Get-Content -Path <path>)))"The resulting process tree is the giveaway: winword.exe (or outlook.exe
rendering a preview) spawns msdt.exe, which itself spawns sdiagnhost.exe,
which then spawns cmd.exe/powershell.exe — a chain that never occurs
during a user's legitimate, manually-invoked troubleshooting wizard.
Detection & analysis
Static analysis:
- On the document itself: an
.docx'sword/_rels/document.xml.relsreferencing an externalTargetMode="External"template URL is the delivery mechanism — the same remote-template-injection primitive covered in Malicious Documents and Archives, applied here to reach a protocol handler instead of a macro.
Dynamic analysis:
- The process lineage
winword.exe/outlook.exe→msdt.exe→sdiagnhost.exe→ a command interpreter is the single strongest signal; legitimate MSDT is launched by the user from Settings, not by Office. - Confirm patch status: post-patch systems require the registered
ms-msdtprotocol's diagnostic pack to be present and unmodified — the official fix removed the vulnerable code path, so a fully patched host simply fails the exploit rather than executing it.
Detection rule hint:
Alert on process creation where ParentImage matches an Office application
or outlook.exe AND Image ends with \msdt.exe, or where msdt.exe's own
command line contains IT_BrowseForFile combined with Invoke-Expression or
similar command-execution syntax.