Skip to content

MSDT Follina Execution

Abusing the ms-msdt: URI protocol handler (CVE-2022-30190, 'Follina') to run arbitrary commands from an Office document without needing macros.

Follina (CVE-2022-30190) abuses the ms-msdt: URI protocol handler, registered by the Microsoft Support Diagnostic Tool, to run arbitrary commands. The distinctive part of this technique is not the payload delivery mechanism — it is that Word can be made to invoke the handler through a document's remote-template feature (word/_rels/document.xml.rels pointing at an external HTML file) without the document containing a macro and without Protected View blocking it, since the template fetch happens before any macro-security prompt would apply.

msdt.exe itself is a signed, ordinary Windows diagnostics tool; the vulnerability is in how the protocol handler passes its parameters to it.

How it works

The HTML fetched via the remote template contains a script that navigates to an ms-msdt: URI carrying an encoded diagnostic parameter, which in turn smuggles a PowerShell command:

text
ms-msdt:/id PCWDiagnostic /skip force /param "IT_RebrowseForFile=cal?c IT_LaunchMethod=ContextMenu IT_SelectProgram=NotListed IT_BrowseForFile=$(Invoke-Expression($(Get-Content -Path <path>)))"

The resulting process tree is the giveaway: winword.exe (or outlook.exe rendering a preview) spawns msdt.exe, which itself spawns sdiagnhost.exe, which then spawns cmd.exe/powershell.exe — a chain that never occurs during a user's legitimate, manually-invoked troubleshooting wizard.

Detection & analysis

Static analysis:

  • On the document itself: an .docx's word/_rels/document.xml.rels referencing an external TargetMode="External" template URL is the delivery mechanism — the same remote-template-injection primitive covered in Malicious Documents and Archives, applied here to reach a protocol handler instead of a macro.

Dynamic analysis:

  • The process lineage winword.exe/outlook.exe → msdt.exe → sdiagnhost.exe → a command interpreter is the single strongest signal; legitimate MSDT is launched by the user from Settings, not by Office.
  • Confirm patch status: post-patch systems require the registered ms-msdt protocol's diagnostic pack to be present and unmodified — the official fix removed the vulnerable code path, so a fully patched host simply fails the exploit rather than executing it.

Detection rule hint:

Alert on process creation where ParentImage matches an Office application or outlook.exe AND Image ends with \msdt.exe, or where msdt.exe's own command line contains IT_BrowseForFile combined with Invoke-Expression or similar command-execution syntax.

Votes

Comments(0)