<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom"><title>Bug Alert - End-User Applications</title><link href="https://bugalert.org/" rel="alternate"></link><link href="https://bugalert.org/feeds/end-user-applications.atom.xml" rel="self"></link><id>https://bugalert.org/</id><updated>2022-05-30T09:00:00+00:00</updated><subtitle>A nonprofit service for alerting security and IT professionals of high-impact and 0day vulnerabilities.</subtitle><entry><title>Remote Code Execution in Microsoft Office Products for Windows</title><link href="https://bugalert.org/content/notices/2022-05-30-office.html" rel="alternate"></link><published>2022-05-30T09:00:00+00:00</published><updated>2022-05-30T09:00:00+00:00</updated><author><name>Bug Alert Contributors</name></author><id>tag:bugalert.org,2022-05-30:/content/notices/2022-05-30-office.html</id><summary type="html">&lt;p&gt;A remote code execution vulnerability, dubbed 'Follina', has been found in Microsoft Office via Microsoft Support Diagnostic Tool (MSDT). This issue can be exploited in the default configuration on Windows, and only requires the user be tricked into downloading a malicious file. There is no patch. This issue has been assigned a bug alert severity of 'high'.&lt;/p&gt;</summary><content type="html">&lt;p&gt;On Monday, May 30th, 2022, &lt;a href="https://doublepulsar.com/follina-a-microsoft-office-code-execution-vulnerability-1a47fce5629e"&gt;security researcher Kevin Beaumont published a blog post&lt;/a&gt; detailing an exploit, 'Follina', that had been discovered three days prior and discussed at length on Twitter. This exploit abuses the template retrieval mechanism in Microsoft Office installations on Microsoft Windows systems to initiate arbitrary code, using a vulnerability in Microsoft Support Diagnostic Tool (MSDT).
On May 30th, 2022, &lt;a href="https://msrc-blog.microsoft.com/2022/05/30/guidance-for-cve-2022-30190-microsoft-support-diagnostic-tool-vulnerability/"&gt;Microsoft acknowledged this issue&lt;/a&gt; and workarounds are available, but there is no patch. This exploit has been actively used against Russia-based targets for over a month.&lt;/p&gt;
&lt;p&gt;Exploit code is widely available online, and weaponization of this vulnerability by groups &lt;em&gt;other than&lt;/em&gt; the original authors is likely already underway. While awaiting patches from Microsoft, the best course of action is to monitor for use of this exploit, provide user education and implement workarounds. Signatures for various detection tools have been made available and are linked from Kevin Beaumont's post. Microsoft has also released detections for Microsoft Defender. This post will be updated as information becomes available.&lt;/p&gt;
&lt;p&gt;This vulnerability has been assigned CVE-2022-30190.&lt;/p&gt;
&lt;p&gt;If you have feedback (did you agree/disagree that a notice should have been sent?) or questions, please comment on the discussion thread linked below. This notice cost the project approximately $50 USD to send. If you would like to support the project, &lt;a href="https://bugalert.org/content/pages/financial-support.html"&gt;you can learn more here&lt;/a&gt;.&lt;/p&gt;</content><category term="End-User Applications"></category><category term="Office"></category><category term="MSDT"></category><category term="Follina"></category><category term="Windows"></category><category term="Microsoft"></category><category term="CVE-2022-30190"></category><category term="High Severity"></category></entry><entry><title>Placeholder for the End-User Applications Category</title><link href="https://bugalert.org/content/notices/2021-12-01-end-user-applications-placeholder.html" rel="alternate"></link><published>2021-12-01T23:00:00+00:00</published><updated>2021-12-01T23:00:00+00:00</updated><author><name>Bug Alert Contributors</name></author><id>tag:bugalert.org,2021-12-01:/content/notices/2021-12-01-end-user-applications-placeholder.html</id><summary type="html"></summary><content type="html">&lt;p&gt;Our site generator requires all categories to have a notice. This is the placeholder for the 'End-User Applications' category.&lt;/p&gt;</content><category term="End-User Applications"></category></entry></feed>