University of Wisconsin–Madison

Category: Cybersecurity Announcements

Cybersecurity Announcement: Microsoft “Follina” zero-day in the wild (CVE-2022-30190)

About the Event A recently discovered zero-day vulnerability in all supported versions of Windows could allow an attacker to execute arbitrary code on affected machines. The flaw, dubbed “Follina”, exists due to improper validation of links containing the Microsoft Support Diagnostic Tool (MSDT) protocol handler. Although the vulnerability was only recently disclosed, it is currently …