References https://thrive.trellix.com/s/article/KB95707?language=zh_CN https://ti.qianxin.com/blog/articles/cve-2022-30190:%20microsoft-windows-wupport-diagnostic-tool%20(msdt)-remote-code-execution-vulnerability-exploit-analysis/ https://blog.nsfocus.net/microsoft-office-msdt-cve-2022-30190/ https://cloud.tencent.com/developer/article/2041978 https://zhuanlan.zhihu.com/p/654017550 https://blog.csdn.net/aihiglh/article/details/125288375 https://www.anquanke.com/post/id/273839 https://www.antiy.cn/research/notice&report/research_report/20220531.html https://nvd.nist.gov/vuln/detail/cve-2022-30190 https://www.microsoft.com/en-us/msrc/blog/2022/05/guidance-for-cve-2022-30190-microsoft-support-diagnostic-tool-vulnerability https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-30190 https://www.fortinet.com/blog/threat-research/analysis-of-follina-zero-day https://www.hackthebox.com/blog/cve-2022-30190-follina-explained https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-30190
Related VulnerabilitiesPoCCVE-2026-58644: Microsoft SharePoint Server - WS-Federation BinaryFormatter Deserialization RCEMicrosoft SharePoint /_layouts/15/ToolPane.aspx 代码执行漏洞(CVE-2025-53770)Microsoft SharePoint Server /_trust/default.aspx 代码执行漏洞(CVE-2026-50522)Microsoft SharePoint Server JWT 权限绕过漏洞(CVE-2026-55040)Windows截图工具NTLM信息泄露漏洞(CVE-2026-33829)Gradio /static//windows/win.ini 文件读取漏洞 (CVE-2026-28414)Windows Shell Link 敏感信息泄露与欺骗漏洞(CVE-2026-25185)PoCCVE-2021-28480: Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)PoCCVE-2021-28481: Microsoft Exchange - Pre-Auth SSRF / ACL Bypass (ProxyNotFound)PoCsharepoint-lists-api-disclosure: Microsoft SharePoint - List API DisclosurePoCCVE-2025-13315: Twonky Server 8.5.2 on Linux and Windows - Log File ExposurePoCsharepoint-layouts-disclosure: Microsoft SharePoint - Layouts DisclosurePoCsharepoint-masterpage-disclosure: Microsoft SharePoint - Master Page Disclosure