当前位置:网站首页>Microsoft Office Word 远程命令执行漏洞(CVE-2022-30190)分析与利用
Microsoft Office Word 远程命令执行漏洞(CVE-2022-30190)分析与利用
2022-06-25 06:41:00 【千里ZLP】
一、漏洞简介
CVE-2022-30190漏洞在2022年5月27日,由nao_sec发现了一个从白俄罗斯IP上传到VirusTotal的恶意Word文档。该文档使用 Microsoft Word 远程模板功能链接恶意 HTML 文件,Winword.exe 程序处理该恶意 HTML 文件中的 js 代码时发现其中使用”ms-msdt”协议的 URL, 随即启动 msdt.exe 程序(Microsoft Support Diagnostics Tool)处理该 URL,导致内嵌在 URL 中的 powershell 命令得到执行。
2022年5月30日,微软公布该漏洞编号 CVE-2022-30190。
漏洞状态
漏洞细节 | 漏洞POC | 漏洞EXP | 在野利用 |
边栏推荐
- Pit encountered by pytorch: why can't l1loss decrease during model training?
- CGLIB动态代理
- OAuth 2.0一键登录那些事
- C#入门教程
- Research on 3D model retrieval method based on two channel attention residual network - Zhou Jie - paper notes
- Four software 2021-10-14 suitable for beginners to draw PCB
- 不同路径II[针对DFS的动态规划改进]
- [distillation] pointdistiller: structured knowledge distillationwards efficient and compact 3D detection
- 机器学习笔记 - 时间序列的线性回归
- CPDA | how to start the growth path of data analysts?
猜你喜欢

PI Ziheng embedded: This paper introduces the multi-channel link mode of i.mxrt timer pit and its application in coremark Test Engineering

Ca-is1200u current detection isolation amplifier has been delivered in batch
![[Batch dos - cmd Command - Summary and Summary] - cmd extension Command, extension Function (CMD / E: on, CMD / E: off)](/img/2b/4495a6cd41a2dd4e7a20ee60b398c9.png)
[Batch dos - cmd Command - Summary and Summary] - cmd extension Command, extension Function (CMD / E: on, CMD / E: off)

Tupu software digital twin 3D wind farm, offshore wind power of smart wind power

test

【批處理DOS-CMD命令-匯總和小結】-cmd擴展命令、擴展功能(cmd /e:on、cmd /e:off)

STL教程4-输入输出流和对象序列化

Sichuan earth microelectronics ca-is1300 isolated operational amplifier for current detection is on the market

realsense d455 semantic_ Slam implements semantic octree mapping

ts环境搭建
随机推荐
VectorDraw Developer Framework 10.10
MySQL facet 01
[single chip microcomputer project training] multipoint temperature wireless acquisition system based on nRF905
Application of point cloud intelligent drawing in intelligent construction site
单位转换-毫米转像素-像素转毫米
一“石”二“鸟”,PCA有效改善机载LiDAR林下地面点部分缺失的困局
國外LEAD域名郵箱獲取途徑
lebel只想前面有星号,但是不想校验
【批处理DOS-CMD命令-汇总和小结】-文件与目录操作命令(md、rd、xcopy、dir、cd、set、move、copy、del、type、sort)
Debian introduction
2265. 统计值等于子树平均值的节点数
对链表进行插入排序[dummy统一操作+断链核心--被动节点]
基于地面点稀少的LiDAR点云的茂密森林蓄积量估算
Ca-is1200u current detection isolation amplifier has been delivered in batch
指南针可以开股票账户吗?安全吗?
Misunderstanding of switching triode
This year, I graduated
Evolution of Alibaba e-commerce architecture
Introduction to Sichuan Tuwei ca-is3082wx isolated rs-485/rs-422 transceiver
El input to add words to the tail