Microsoft Releases a Windows Update to Fix 'Follina' Vulnerability Actively Exploited by Hackers

Shortly after the vulnerability became public, China-backed hackers were able to exploit it to target some Tibetan users.

Advertisement
By Jagmeet Singh | Updated: 16 June 2022 14:25 IST
Highlights
  • Microsoft has made the update for users on Windows 7 and later
  • Windows update fixes the issue impacting MSDT component
  • Microsoft was first made aware about the vulnerability in April

Microsoft has urged Windows users to install the update

Photo Credit: Reuters

Microsoft has finally released a Windows security fix for the vulnerability that has actively been exploited by hackers. The issue, which was named "Follina" by security researchers, was publicly disclosed last month, though it was initially reported to the Redmond company in April. It enables attackers to hack Windows PCs using a maliciously crafted Microsoft Word document. The security update is available for users on Windows 7 and later. Microsoft has urged users to install the update "as soon as possible" to restrict attackers from gaining access to their systems.

Windows users should install the update by going to the Settings. The update has also been released for systems that are configured to receive automatic updates, Microsoft said in an update to its security advisory.

Advertisement

"Microsoft strongly recommends that customers install the updates to be fully protected from the vulnerability," the company noted.

As reported last month, the security issue, which has been tracked as CVE-2022-30190, was disclosed on Twitter by Tokyo-based cybersecurity researcher team Nao_sec. It initially appeared to be impacting Microsoft Office, though Microsoft acknowledged that the flaw was related to Microsoft Diagnostic Tool (MSDT) that comes preloaded on Windows operating system.

Advertisement

Attackers would be able to exploit the vulnerability by executing PowerShell commands and eventually gain control of the MSDT.

Shortly after it became public, the severe vulnerability was found to be exploited by China-based hackers by using malicious Word documents to Tibetan users. When the documents are accessed, the attackers would be able to leverage the exploit to gain MSDT access and run tasks including installation of certain programs or creation of new user accounts.

Advertisement

As reported by Bleeping Computer, the latest update doesn't restrict Microsoft Office from loading Windows URI handlers without user interactions. It, however, limits attackers to get the control of MSDT by executing PowerShell commands.

The security update is available to all users who have a system running Windows 7 or later. Windows 10 versions have received it as KB5014699, while the update is available as KB5014697 on Windows 11 systems.


This week on Orbital, the Gadgets 360 podcast, we discuss the Surface Pro 8, Go 3, Duo 2, and Laptop Studio — as Microsoft sets a vision for Windows 11 hardware. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Amazon Prime Day Sale Dates Announced, Drops Prime Membership Price
  2. Oppo Reno 16 Series Will Launch in Indonesia, Malaysia on These Dates
  3. JBL Live 780NC, Live 680NC Debut in India With Up to 80-Hour Battery Life
  4. Tim Cook Says Apple Can No Longer Absorb Soaring Memory Costs Alone
  5. Vivo Y6e 5G With 6,500mAh Battery Debuts at This Price
  6. ChatGPT's Grip on AI Assistant Market Weakens Despite Record User Base
  7. Oppo Reno 15A 5G Arrives With a 7,000mAh Battery at This Price
  8. Samsung Galaxy Z Fold 8 Series Might Debut at a Higher Price Than Fold 7
  9. Vivo X Fold 6 Battery, Durability Details Teased Days Ahead of Debut
  10. Xiaomi Wants a Bigger Space in Your Home: Large Appliance Push Confirmed
  1. Chandra Captures Sharpest-Ever X-Ray View of M87 Black Hole Jet
  2. Honor 600 Smart 5G With 7,700mAh Battery Listed on French Website, Could Launch Soon: Price, Features
  3. Rockstar Games Confirms GTA 6 Pre-Orders Will Begin June 25, Reveals New Cover Art
  4. Oppo Enco Air 5 India Launch Teased; Amazon Availability Confirmed
  5. Huawei FreeBuds 7i, FreeBuds SE 4 ANC Launched in India With Up to 50 Hours of Total Battery Life: Price, Features
  6. Aztec Hit With Second Security Breach, Days After Hackers Used Exploit to Steal $2.19 Million
  7. FilterCopy’s For The Real Me Season 1 Now on Instagram: Know Everything About This Micro-Drama Reel Series
  8. Narwal S20, S20 Pro, S30 Wet and Dry Vacuum Cleaners With Up to 20,000Pa Suction Launched in India:Price, Features
  9. Oppo Reno 16 Series Launch Date in Indonesia, Malaysia Announced as Pre-Orders Begin
  10. Vivo Y6e 5G Launched With 6,500mAh Battery, Snapdragon 4 Gen 2 SoC: Price, Specifications
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.