{"id":"CVE-2022-30190","title":"A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word","summary":"A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the c…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","vendor":"microsoft","product":"windows_10_1507","affected":["windows_10_1507 < 10.0.10240.19325","windows_10_1607 < 10.0.14393.5192","windows_10_1809 < 10.0.17763.3046","windows_10_20h2 < 10.0.19042.1766","windows_10_21h1 < 10.0.19043.1766","windows_10_21h2 < 10.0.19044.1766","windows_11_21h2 < 10.0.22000.739","windows_7","windows_8.1","windows_rt_8.1","windows_server_2008 = r2","windows_server_2012","windows_server_2012 = r2","windows_server_2016 < 10.0.14393.5192","windows_server_2019 < 10.0.17763.3046","windows_server_2022 < 10.0.20348.770","windows_server_20h2 < 10.0.19042.1766"],"patched":["windows_10_1507 10.0.10240.19325","windows_10_1607 10.0.14393.5192","windows_10_1809 10.0.17763.3046","windows_10_20h2 10.0.19042.1766","windows_10_21h1 10.0.19043.1766","windows_10_21h2 10.0.19044.1766","windows_11_21h2 10.0.22000.739","windows_server_2016 10.0.14393.5192","windows_server_2019 10.0.17763.3046","windows_server_2022 10.0.20348.770","windows_server_20h2 10.0.19042.1766"],"published":"2022-06-01","updated":"2026-08-04","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2022-30190","references":[{"url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-30190","label":"secure@microsoft.com"},{"url":"http://packetstormsecurity.com/files/167438/Microsoft-Office-Word-MSDTJS-Code-Execution.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-30190","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-30190","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild","exploit-available"],"epss":0.99234,"epssPercentile":0.99936,"kev":true,"kevDateAdded":"2022-06-14","kevDueDate":"2022-07-05","kevRansomware":true,"exploited":true,"zeroDay":true,"ingestedAt":"2026-08-04T05:36:12.305Z","exploits":{"github":94,"githubRepos":["https://github.com/JMousqueton/PoC-CVE-2022-30190","https://github.com/onecloudemoji/CVE-2022-30190","https://github.com/2867a0/CVE-2022-30190"],"metasploit":["exploit/windows/fileformat/word_msdtjs_rce"],"checkedAt":"2026-09-21T15:25:23.799Z"},"exploitAvailable":true,"slug":"CVE-2022-30190","body":"## Overview\n\nA remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling application. The attacker can then install programs, view, change, or delete data, or create new accounts in the context allowed by the user’s rights.\nPlease see the MSRC Blog Entry for important information about steps you can take to protect your system from this vulnerability.\n\n## Affected\n\n- `windows_10_1507 < 10.0.10240.19325`\n- `windows_10_1607 < 10.0.14393.5192`\n- `windows_10_1809 < 10.0.17763.3046`\n- `windows_10_20h2 < 10.0.19042.1766`\n- `windows_10_21h1 < 10.0.19043.1766`\n- `windows_10_21h2 < 10.0.19044.1766`\n- `windows_11_21h2 < 10.0.22000.739`\n- `windows_7`\n- `windows_8.1`\n- `windows_rt_8.1`\n- `windows_server_2008 = r2`\n- `windows_server_2012`\n- `windows_server_2012 = r2`\n- `windows_server_2016 < 10.0.14393.5192`\n- `windows_server_2019 < 10.0.17763.3046`\n- `windows_server_2022 < 10.0.20348.770`\n- `windows_server_20h2 < 10.0.19042.1766`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `windows_10_1507 10.0.10240.19325`\n- `windows_10_1607 10.0.14393.5192`\n- `windows_10_1809 10.0.17763.3046`\n- `windows_10_20h2 10.0.19042.1766`\n- `windows_10_21h1 10.0.19043.1766`\n- `windows_10_21h2 10.0.19044.1766`\n- `windows_11_21h2 10.0.22000.739`\n- `windows_server_2016 10.0.14393.5192`\n- `windows_server_2019 10.0.17763.3046`\n- `windows_server_2022 10.0.20348.770`\n- `windows_server_20h2 10.0.19042.1766`","depth":"abyssal","depthScore":93,"depthScoreParts":{"impact":42.9,"likelihood":19.8,"exploitation":25,"ransomware":5},"changes":[{"seq":4622,"id":"CVE-2022-30190","ts":1788887194306,"field":"exploit_available","old":"false","new":"true"},{"seq":3505,"id":"CVE-2022-30190","ts":1788886310781,"field":"exploit_available","old":"true","new":"false"},{"seq":2359,"id":"CVE-2022-30190","ts":1788882980234,"field":"exploit_available","old":"false","new":"true"},{"seq":1388,"id":"CVE-2022-30190","ts":1788882392878,"field":"exploit_available","old":"true","new":"false"},{"seq":502,"id":"CVE-2022-30190","ts":1788881828733,"field":"exploit_available","old":"false","new":"true"}]}