← back
CVE-2022-34713

Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability

CVSS 7.8 HIGHEPSS 68.0%● KEV
Vexday Risk Score
63High priority
SSVC decision (CISA)
Act
Exploitation + impact → act immediately
CVSS 7.8EPSS 68.0%KEV simPoC Nuclei Metasploit Patch referenciado
Lifecycle
09 Aug 2022Active exploitation (CISA KEV)
09 Aug 2022Published on NVD
Recommendation: Patch as soon as possible — active exploitation confirmed.
In short

A flaw in Microsoft's Windows Support Diagnostic Tool allows attackers to run malicious code on your computer through specially crafted files or links. This is dangerous because it can give attackers full control of your system without your knowledge.

Technical detail

CVE-2022-34713 is a remote code execution vulnerability in MSDT exploitable via malicious URI schemes or specially crafted documents (e.g., Office files with embedded ms-msdt:// links). The attack requires user interaction to open the malicious file but bypasses UAC protections, allowing arbitrary code execution in the context of the calling process.

Summary generated and translated by AI from the official description.
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →