当前位置:网站首页>Microsoft Office Word 远程命令执行漏洞(CVE-2022-30190)分析与利用
Microsoft Office Word 远程命令执行漏洞(CVE-2022-30190)分析与利用
2022-06-25 06:41:00 【千里ZLP】
一、漏洞简介
CVE-2022-30190漏洞在2022年5月27日,由nao_sec发现了一个从白俄罗斯IP上传到VirusTotal的恶意Word文档。该文档使用 Microsoft Word 远程模板功能链接恶意 HTML 文件,Winword.exe 程序处理该恶意 HTML 文件中的 js 代码时发现其中使用”ms-msdt”协议的 URL, 随即启动 msdt.exe 程序(Microsoft Support Diagnostics Tool)处理该 URL,导致内嵌在 URL 中的 powershell 命令得到执行。
2022年5月30日,微软公布该漏洞编号 CVE-2022-30190。
漏洞状态
漏洞细节 | 漏洞POC | 漏洞EXP | 在野利用 |
边栏推荐
- OpenMP入门
- Tupu software digital twin 3D wind farm, offshore wind power of smart wind power
- (tool class) use SecureCRT as the communication medium
- Home environment monitoring system design (PC version) (mobile app version to be determined)
- 微信小程序入门记录
- Keil and Proteus joint commissioning
- OAuth 2.0一键登录那些事
- 【Qt】快捷键
- RTKLIB-b33版本中GALILEO广播星历存储问题
- AttributeError: ‘Upsample‘ object has no attribute ‘recompute_scale_factor‘
猜你喜欢

Four software 2021-10-14 suitable for beginners to draw PCB

Path planner based on time potential function in dynamic environment

MySQL facet 01

Without "rice", you can cook "rice". Strategy for retrieving missing ground points under airborne lidar forest using "point cloud intelligent mapping"

Chuantu microelectronics 𞓜 subminiature package isolated half duplex 485 transceiver

【蒸馏】PointDistiller: Structured Knowledge DistillationTowards Efficient and Compact 3D Detection
![[batch dos-cmd command - summary and summary] - add comment command (REM or::)](/img/e9/151885ecd490b0aa83cce0f3a49124.png)
[batch dos-cmd command - summary and summary] - add comment command (REM or::)

smartBugs安装小问题总结
![[single chip microcomputer project training] multipoint temperature wireless acquisition system based on nRF905](/img/a7/fc5d2f4640322a5d7222cce83c8898.jpg)
[single chip microcomputer project training] multipoint temperature wireless acquisition system based on nRF905

CPDA | how to start the growth path of data analysts?
随机推荐
Modular programming of wireless transmission module nRF905 controlled by single chip microcomputer
Static bit rate (CBR) and dynamic bit rate (VBR)
Elk + filebeat log parsing, log warehousing optimization, logstash filter configuration attribute
realsense d455 semantic_slam实现语义八叉树建图
Can I open a stock account with a compass? Is it safe?
Four software 2021-10-14 suitable for beginners to draw PCB
CPDA | how to start the growth path of data analysts?
Cglib dynamic proxy
Runtime——methods成员变量,cache成员变量
Chuantuwei ca-is3720lw alternative material No. iso7820fdw
ts环境搭建
npm install 报错 : gyp ERR! configure error
shell小技巧(一百三十四)简单的键盘输入记录器
Hisilicon 3559 sample parsing: Vio
Function template_ Class template
Distributed quorum NWR of the alchemy furnace of the Supreme Master
Full range of isolator chips with integrated isolated power supply
MySQL facet 01
Introduction to Sichuan Tuwei ca-is3082w isolated rs-485/rs-422 transceiver
el-input实现尾部加字