PULSE
EN VIVO0señales / 24h
FEED
vulnKEV agrega CVE-2023-49105 — ownCloud / ownCloudvulnKEV agrega CVE-2026-53362 — Linux / KernelvulnKEV agrega CVE-2026-66384 — JFrog / ArtifactoryvulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET ProfessionalvulnKEV agrega CVE-2015-3246 — Red Hat / LibuservulnKEV agrega CVE-2015-5287 — Red Hat / Automatic Bug Reporting ToolvulnKEV agrega CVE-2022-0995 — Linux / KernelvulnKEV agrega CVE-2026-8452 — Citrix / NetScaler ADC and NetScaler GatewayvulnKEV agrega CVE-2019-1068 — Microsoft / SQL ServervulnKEV agrega CVE-2026-60004 — Gitea / GiteavulnKEV agrega CVE-2026-21962 — Oracle / HTTP Server and Oracle Weblogic Server Proxy Plug-invulnKEV agrega CVE-2026-73570 — Synacor / Zimbra Collaboration Suite (ZCS)vulnKEV agrega CVE-2026-72530 — TrueConf / ServervulnKEV agrega CVE-2026-72529 — TrueConf / ServervulnKEV agrega CVE-2023-49105 — ownCloud / ownCloudvulnKEV agrega CVE-2026-53362 — Linux / KernelvulnKEV agrega CVE-2026-66384 — JFrog / ArtifactoryvulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET ProfessionalvulnKEV agrega CVE-2015-3246 — Red Hat / LibuservulnKEV agrega CVE-2015-5287 — Red Hat / Automatic Bug Reporting ToolvulnKEV agrega CVE-2022-0995 — Linux / KernelvulnKEV agrega CVE-2026-8452 — Citrix / NetScaler ADC and NetScaler GatewayvulnKEV agrega CVE-2019-1068 — Microsoft / SQL ServervulnKEV agrega CVE-2026-60004 — Gitea / GiteavulnKEV agrega CVE-2026-21962 — Oracle / HTTP Server and Oracle Weblogic Server Proxy Plug-invulnKEV agrega CVE-2026-73570 — Synacor / Zimbra Collaboration Suite (ZCS)vulnKEV agrega CVE-2026-72530 — TrueConf / ServervulnKEV agrega CVE-2026-72529 — TrueConf / Server
← Todos los CVEs
CVE Watch6 ago 2026

CVE-2022-30190

Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability

CVSS

7.8

Alto

EPSS

99.2%

p100

KEV

14 jun 2022

Exploit Today

80

0-100

Publicado: 1 jun 2022 · Última mod.: 6 ago 2026

EPSS · 30d
99.2%EPSS · 30 días99.4%
2026-08-022026-08-30
Ficha del catálogo KEV

Producto

Microsoft / Windows

Vulnerabilidad

Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability

Añadido a KEV

14 jun 2022

Remediar antes de

5 jul 2022

Uso conocido en ransomware

Descripción resumida

A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run code with the privileges of the calling application.

Acción requerida

Apply updates per vendor instructions.

Notas

https://nvd.nist.gov/vuln/detail/CVE-2022-30190

Descripción técnica

A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling application. The attacker can then install programs, view, change, or delete data, or create new accounts in the context allowed by the user’s rights. Please see the MSRC Blog Entry for important information about steps you can take to protect your system from this vulnerability.

Referencias oficiales
CVEs relacionados
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-322024.3 MED
99.2%
KEV80Microsoft Windows Protection Mechanism Failure Vulnerability17d
CVE-2026-208055.5 MED
91.8%
KEV78Microsoft Windows Information Disclosure Vulnerability31d
CVE-2025-266337.0 ALT
98.1%
KEV79Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability26d
CVE-2024-490398.8 ALT
96.3%
KEV79Microsoft Windows Task Scheduler Privilege Escalation Vulnerability27d
CVE-2024-434618.8 ALT
98.9%
KEV80Microsoft Windows MSHTML Platform Spoofing Vulnerability21d
CVE-2024-382175.4 MED
95.3%
KEV79Microsoft Windows Mark of the Web (MOTW) Protection Mechanism Failure Vulnerability21d