China-backed hackers are exploiting an unpatched Microsoft Office zero-day vulnerability, known as “Follina”, to execute malicious code remotely on Windows systems. The high-severity vulnerability – tracked as CVE-2022-30190 – is being used in attacks to execute malicious PowerShell commands via the Microsoft Diagnostic Tool (MSDT) when opening or previewing specially crafted Office documents. The flaw, which […]
Chinese-linked threat actors are now actively exploiting a Microsoft Office zero-day vulnerability (known as Follina ) to execute malicious code remotely on Windows systems.
The high-severity vulnerability affects 41 Microsoft products, including Office 365 and Windows 11. China-backed hackers are attacking the unpatched version of Microsoft Office's zero-day vulnerability, which is called "Follina," and carrying out malicious code remotely on various Windows systems.