MicrosoftNews/PR

Microsoft issues guidelines to tackle vulnerability Follina

1 Mins read
Follina

Microsoft issued CVE-2022-30190, a zero-day remote code execution (RCE) vulnerability referred to as “Follina”, regarding the Microsoft Support Diagnostic Tool (MSDT) in Windows vulnerability, on Monday, May 30, 2022.

“A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling application. The attacker can then install programs, view, change, or delete data, or create new accounts in the context allowed by the user’s rights”, said Microsoft Security Response Center (MSRC) in its blog.

Office documents seem to be a popular choice for cybercriminals to attack users with their malicious content. This vulnerability “Follina” just requires the user to open a single document with no necessity for further interactions. This attack does not rely on macros. The malicious code is executed even if macros are disabled.

How to stay safe from Follina

Microsoft has issued guidelines for users on how to apply a workaround to stay protected from Follina.

It recommends disabling the MSDT URL Protocol which will prevent troubleshooters like links from being launched throughout the operating system.

To disable the MSDT URL Protocol, first, you need to run Command Prompt as Administrator. Then back up the registry key and execute the command “reg export HKEY_CLASSES_ROOT\ms-msdt filename”. As the last step, execute the command “reg delete HKEY_CLASSES_ROOT\ms-msdt /f”.

Users can undo the workaround by restoring the registry key by executing the command “reg import filename”.

Microsoft also recommends its customers with Microsoft Defender Antivirus to turn on cloud-delivered protection and automatic sample submission. These capabilities will quickly identify and stop new and unknown threats using artificial intelligence and machine learning.

It is preferred that all devices with internet access should be protected using comprehensive security tools so that users can prevent security attacks on their system if anyone exploits any unknown vulnerability.

Read next: Microsoft estimates double-digit revenue growth driven by strong demand for cloud services

Leave a Reply

Your email address will not be published. Required fields are marked *

5 × = 10