当前位置:网站首页>Analysis and utilization of Microsoft Office Word remote command execution vulnerability (cve-2022-30190)
Analysis and utilization of Microsoft Office Word remote command execution vulnerability (cve-2022-30190)
2022-06-25 07:50:00 【Qianli ZLP】
One 、 Vulnerability profile
CVE-2022-30190 Holes in the 2022 year 5 month 27 Japan , from nao_sec Found one from Belarus IP Upload to VirusTotal Malice Word file . This document uses Microsoft Word Remote template function link malicious HTML file ,Winword.exe The program handles the malicious HTML In the document js Code found using ”ms-msdt” Agreed URL, Then start msdt.exe Program (Microsoft Support Diagnostics Tool) Handle the URL, Cause embedded in URL Medium powershell The command is executed .
2022 year 5 month 30 Japan , Microsoft released the vulnerability number CVE-2022-30190.
Vulnerability status
Vulnerability details | Loophole POC | Loophole EXP | Use in the field |
边栏推荐
猜你喜欢

Three years of continuous decline in revenue, Tiandi No. 1 is trapped in vinegar drinks

NPM install reports an error: gyp err! configure error

Basic use of ActiveMQ in Message Oriented Middleware

Shell tips (134) simple keyboard input recorder

Leetcode daily question - 515 Find the maximum value in each tree row

用函数的递归来解决几道有趣的题

Understand the reasons for impedance matching of PCB circuit board 2021-10-07

Share the process requirements for single-layer flexible circuit board

Tupu software digital twin 3D wind farm, offshore wind power of smart wind power

一文了解 | 革兰氏阳性和阴性菌区别,致病差异,针对用药
随机推荐
c# winform panel自定义图片和文字
"Spatial transformation" significantly improves the quality of ground point extraction of cliff point cloud
一文了解 | 革兰氏阳性和阴性菌区别,致病差异,针对用药
GUI pull-down menu of unity3d evil door implementation dropdown design has no duplicate items
力扣76题,最小覆盖字串
Storage of Galileo broadcast ephemeris in rtklib-b33
Cglib dynamic proxy
VSCode很好,但我以后不会再用了
Accès à la boîte aux lettres du nom de domaine Lead à l'étranger
AttributeError: ‘Upsample‘ object has no attribute ‘recompute_scale_factor‘
How much do you know about electronic components on PCB?
C# 读取web上的xml
Different paths ii[dynamic planning improvement for DFS]
Construction of occupancy grid map
判断用户是否是第一次进入某个页面
【日常训练】207. 课程表
【QT】qtcreator便捷快捷键以及QML介绍
Mysql面试-执行sql响应比较慢,排查思路。
权限、认证系统相关名词概念
Misunderstanding of switching triode