Originally published: 06/16/2022
Microsoft has recently established a workaround for a zero-day vulnerability, known as Follina, affecting Microsoft Office applications, such as Word, after it was originally identified in April. This vulnerability is a remote code execution (RCE) flaw, and if successfully exploited, threat actors can install programs, view, modify, or delete data on targeted systems. The RCE is associated with the Microsoft Support Diagnostic Tool (MSDT), which, ironically, collects information about bugs in the company’s products and reports them to Microsoft Support.
Microsoft explained that “a remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word…An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling application”.[1] The workaround came about six weeks after researchers from Shadow Chaser Group first observed the vulnerability on April 12th and reported it to Microsoft on April 21st. The vulnerability was noticed in a bachelor’s thesis from August 2020, with attackers seemingly targeting Russian users.[2] A Malwarebytes Threat Intelligence analyst also found the flaw back in April, but could not fully identify it. The company posted a tweet on the same day, April 12th.[2]
At first, when the flaw was reported, Microsoft did not consider it an issue. But now, it is clear that the vulnerability should be taken seriously, with Japanese security vendor Nao Sec tweeting a fresh warning, noting that the vulnerability was targeting users in Belarus. Security researcher Kevin Beaumont called the vulnerability Follina; the name comes from the zero-day code references to the Italy-based area code of Follina (0438).[2]
There is no fix for the flaw, but Microsoft recommends that affected users disable the MSDT URL for now. Disabling the MSDT URL “prevents troubleshooters from being launched as links, including links throughout the operating system.”[2] To disable the MSDT URL, users should follow these steps:
Microsoft says that the troubleshooters can still be accessed via the Get Help application and the system settings. Microsoft also says that if the calling application is an Office program, Office will open the document in Protected View and Application Guard for Office, which Microsoft says will “prevent the current attack.” However, Beaumont refuted that assurance in his analysis of the bug.[2] Microsoft also plans to update CVE-2022-3019 with further information, but did not specify when it would do so.[2]
Meanwhile, the unpatched flaw poses a significant threat. One reason is that the flaw affects a large number of people, given that it exists in all currently supported Windows versions and can be exploited via Office versions 2013-2019, Office 2021, Office 365, and Office ProPlus.[2] Another reason is that the flaw poses a major threat in its execution without action from the end-user. Once the HTML is loaded from the calling application, an MSDT scheme executes PowerShell code that runs a malicious payload.[2] Since the flaw abuses the remote template feature in Microsoft Word, it is not dependent on a typical macro-based exploit path, which is common in Office-based attacks.[2]
Researchers say that this flaw is similar to last year’s zero-click MSHTML bug (CVE-2021-40444), which was pummeled by attackers, including the Ryuk ransomware gang. In fact, threat actors already pounced on this vulnerability. Proofpoint Threat Insight tweeted that threat actors were using the vulnerability to target organizations in Tibet by impersonating the “Women Empowerments Desk” of the Central Tibetan Administration. Moreover, the workaround Microsoft currently offers has issues and won’t provide much of a long-term fix. It is not user-friendly for admins because the workaround requires users to modify the Windows Registry, says Aviv Grafti, CTO and founder of Votiro.[2]
Because the HTTP GET request headers are out of order relative to “typical” patterns, a custom-developed DDoS attack tool is assumed to be used, and the values may change between campaigns. As such, Larry Cashdollar, a researcher at Akamai, says that writing signatures for these patterns may not benefit defenders from an IOC standpoint. More information can be found at the link below:
https://www.akamai.com/blog/security/revil-resurgence-or-copycat
(1) Microsoft Security Response Center, ed. “Guidance for CVE-2022-30190 Microsoft Support Diagnostic Tool Vulnerability.” Microsoft Security Response Center, May 30, 2022. https://msrc-blog.microsoft.com/2022/05/30/guidance-for-cve-2022-30190-microsoft-support-diagnostic-tool-vulnerability/.
(2) Montalbano, Elizabeth. “Microsoft Releases Workaround for ‘One-Click’ 0Day Under Active Attack.” Threatpost English Global, June 1, 2022. https://threatpost.com/microsoft-workaround-0day-attack/179776/.Threat Advisory created by the Cyber Florida Security Operations Center.
Contributing Security Analysts: Dorian Pope, Sreten Dedic, EJ Bulut, Uday Bilakhiya, Tural Hagverdiyev.