CyberSec.Space Logo
返回 CVE 浏览器

CVE-2022-30190

🔥 Known Exploited (CISA KEV)HIGH
7.8
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2022-06-01
Last Modified2026-06-17
Data SourcesNVDCISA KEV

Vulnerability Description

A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling application. The attacker can then install programs, view, change, or delete data, or create new accounts in the context allowed by the user’s rights. Please see the MSRC Blog Entry for important information about steps you can take to protect your system from this vulnerability.

Affected Platforms (CPE)

💻
Microsoft

Windows 10 1507

< 10.0.10240.19325
💻
Microsoft

Windows 10 1607

< 10.0.14393.5192
💻
Microsoft

Windows 10 1809

< 10.0.17763.3046
💻
Microsoft

Windows 10 20h2

< 10.0.19042.1766

References & Advisories

相關資安分析文章

相关漏洞威胁