Microsoft Office Impacted With 'Follina' Zero-Day Vulnerability: Researchers

Attackers are found to have already exploited the vulnerability and targeted some users.

Advertisement
By Jagmeet Singh | Updated: 31 May 2022 13:29 IST
Highlights
  • Microsoft Office vulnerability was publicly disclosed on May 27
  • Attackers could exploit the vulnerability for code execution
  • Microsoft has acknowledged the issue and shared some workarounds

Microsoft Office users are at risk due to the "Follina" vulnerability

Photo Credit: Microsoft

Microsoft Office is found to have a zero-day vulnerability that can allow attackers to execute code using a specially crafted Word file. Called Follina, the security issue can impact users the moment they open the malicious Word document on their system. It enables attackers to execute PowerShell commands via Microsoft Diagnostic Tool (MSDT). Office 2013 and later versions are impacted by the Follina zero-day vulnerability, according to researchers. Microsoft has not yet brought its fix.

Tokyo-based cybersecurity research team Nao_sec publicly disclosed the Follina vulnerability impacting Microsoft Office on Twitter last week. Per the explanation provided by the researchers, the issue is allowing Microsoft Word to execute a malicious code via MSDT even if macros are disabled.

Microsoft provides macros as a series of commands and instructions that users can use to automate a particular task. However, the new vulnerability has enabled attackers to process a similar kind of automation, without using macros.

Advertisement

"The document uses the Word remote template feature to retrieve a HTML file from a remote Web server, which in turn uses the ms-msdt MSProtocol URI scheme to load some code and execute some PowerShell," explains researcher Kevin Beaumont, who examined the issue raised by Nao_sec. "That should not be possible."

Advertisement

Beaumont has named the vulnerability "Follina" since the spotted sample on the file references 0438, which is the area code of Italy's Follina.

The vulnerability is believed to be exploited in the wild by some attackers.

Advertisement

Beaumont said that a file exploiting the loophole targeted a user in Russia over a month ago.

Microsoft Office versions including Office 2013 as well as Office 2021 are found to be vulnerable to attacks due to the issue. Some versions of Office included with a Microsoft 365 licence could also be targeted by attackers on both Windows 10 and Windows 11, the researchers have pointed out.

Advertisement

Initially, Microsoft was informed about the vulnerability in April, though the company did not consider it a security issue at the time, a security researcher on Twitter reports.

Microsoft, however, finally acknowledged the existence of the vulnerability on Monday. It is tracked as CVE-2022-30190.

In a post released on the Microsoft Security Response Center blog, the Redmond company also shared some workarounds, including the option to disable the MSDT URL protocol and turning on the turn-on cloud-delivered protection and automatic sample submission options on Microsoft Defender.

However, Microsoft has not yet provided an exact timeline on when we could see the fix coming for Office users.

Users, in the meantime, can stay safe by not opening any unknown Microsoft Word documents if they have an affected Office version on a Windows machine.


Asus India's Arnold Su joins this week's Orbital, the Gadgets 360 podcast, to talk about how the PC maker is planning to grow its presence in the country. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

For details of the latest launches and news from Samsung, Xiaomi, Realme, OnePlus, Oppo and other companies at the Mobile World Congress in Barcelona, visit our MWC 2025 hub.

Advertisement

Related Stories

Popular Mobile Brands
  1. Nothing Phone 4a Pro Teaser Hints at the Presence of This Phone 3 Feature
  2. Realme Narzo Power 5G With 10,001mAh Battery Launched in India: Price, Specifications
  3. Infinix Note 60 Ultra With Pininfarina Design Launched at MWC 2026
  4. Moto Watch Review: The Best Smartwatch Under Rs. 6,000 in 2026?
  5. iPhone 17e vs iPhone 17: Price in India, Features, Specifications Compared
  6. OnePlus 15T Confirmed to Launch With a Larger Battery, Faster Charging
  7. Vivo T5x 5G AnTuTu Score Exceeds 1 Million Points, Will Launch in India Soon
  8. OnePlus 16, iQOO 16, Redmi K100 Pro Max Tipped to Launch at Higher Prices
  9. Samsung Galaxy A37, Galaxy A57 Get Better Geekbench Scores Ahead of Debut
  10. MacBook Neo Launched in India With 13-Inch Display, A18 Pro Chip: See Price
  1. Granny OTT Release Date: When and Where to Watch the Village Mystery Thriller Online?
  2. Andhaka OTT Release: Where to Watch the Telugu Drama-Thriller Online?
  3. Pookie OTT Release: When and Where to Watch Vijay Antony’s Romantic Drama Online?
  4. WhatsApp Plus Paid Subscription Reportedly in Development With Additional Customisation Options, Up to 20 Pinned Chats
  5. Samsung Patent Hints at Potential Clamshell-Style Foldable With Two Cover Displays
  6. Google Introduces Gemini 3.1 Flash-Lite as Its Fastest and Most Cost-Efficient AI Model
  7. Oppo Find N6 Key Features, Colour Options Leaked Ahead of Imminent China Launch
  8. Honor 600 Lite Launched With MediaTek Dimensity 7100 Elite, 6,520mAh Battery: Price, Specifications
  9. Vivo T5x 5G Teased to Launch in India Soon; Company Says AnTuTu Score Exceeds 1 Million Points
  10. MWC 2026: Oppo, MediaTek Join Hands to Showcase New On-Device AI Capabilities for Future Smartphones
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.