Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-30190


A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling application. The attacker can then install programs, view, change, or delete data, or create new accounts in the context allowed by the user’s rights. Please see the MSRC Blog Entry for important information about steps you can take to protect your system from this vulnerability.


Published

2022-06-01T20:15:07.983

Last Modified

2025-10-30T19:19:41.540

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

8.6

Impact Score

10.0

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System microsoft windows_10_1507 < 10.0.10240.19325 Yes
Operating System microsoft windows_10_1607 < 10.0.14393.5192 Yes
Operating System microsoft windows_10_1809 < 10.0.17763.3046 Yes
Operating System microsoft windows_10_20h2 < 10.0.19042.1766 Yes
Operating System microsoft windows_10_21h1 < 10.0.19043.1766 Yes
Operating System microsoft windows_10_21h2 < 10.0.19044.1766 Yes
Operating System microsoft windows_11_21h2 < 10.0.22000.739 Yes
Operating System microsoft windows_7 - Yes
Operating System microsoft windows_8.1 - Yes
Operating System microsoft windows_rt_8.1 - Yes
Operating System microsoft windows_server_2008 r2 Yes
Operating System microsoft windows_server_2012 - Yes
Operating System microsoft windows_server_2012 r2 Yes
Operating System microsoft windows_server_2016 < 10.0.14393.5192 Yes
Operating System microsoft windows_server_2019 < 10.0.17763.3046 Yes
Operating System microsoft windows_server_2022 < 10.0.20348.770 Yes
Operating System microsoft windows_server_20h2 < 10.0.19042.1766 Yes

References