{"id":582,"date":"2022-06-02T11:39:55","date_gmt":"2022-06-02T11:39:55","guid":{"rendered":"https:\/\/t3x.co.uk\/?p=582"},"modified":"2022-06-02T11:39:55","modified_gmt":"2022-06-02T11:39:55","slug":"cve-2022-30190-exploit","status":"publish","type":"post","link":"https:\/\/t3x.co.uk\/?p=582","title":{"rendered":"CVE-2022-30190 Exploit"},"content":{"rendered":"\n<p>This refers to a means of launching the Microsoft Support Diagnostics Tool (MSDT) which can be via a URI from a malicious source avoiding normal security checks including browser protected mode.  <\/p>\n\n\n\n<!--more-->\n\n\n\n<p>This tool is for getting support directly from Microsoft or one of their official partners to help a user who is experiencing problems.  Malicious use of this tool can give the exploiter access to PowerShell on your Windows computer which is never a good thing. <\/p>\n\n\n\n<p>The tool is normally launched directly but can be launched in a browser using the special protocol <strong>ms-msdt:\/\/<\/strong><\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/t3x.co.uk\/wp-content\/uploads\/2022\/06\/3.jpg\" alt=\"\" class=\"wp-image-583\" width=\"582\" height=\"501\" srcset=\"https:\/\/t3x.co.uk\/wp-content\/uploads\/2022\/06\/3.jpg 583w, https:\/\/t3x.co.uk\/wp-content\/uploads\/2022\/06\/3-300x258.jpg 300w\" sizes=\"auto, (max-width: 582px) 100vw, 582px\" \/><\/figure>\n<\/div>\n\n\n<p>Microsoft has published a work around until a patch is provided which is basically disabling the tool.  <a href=\"https:\/\/msrc-blog.microsoft.com\/2022\/05\/30\/guidance-for-cve-2022-30190-microsoft-support-diagnostic-tool-vulnerability\/\">Link here<\/a>.<\/p>\n\n\n\n<p>The basic procedure:<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"439\" height=\"354\" src=\"https:\/\/t3x.co.uk\/wp-content\/uploads\/2022\/06\/1.jpg\" alt=\"\" class=\"wp-image-584\" srcset=\"https:\/\/t3x.co.uk\/wp-content\/uploads\/2022\/06\/1.jpg 439w, https:\/\/t3x.co.uk\/wp-content\/uploads\/2022\/06\/1-300x242.jpg 300w\" sizes=\"auto, (max-width: 439px) 100vw, 439px\" \/><figcaption>Run command prompt in admin mode<\/figcaption><\/figure>\n<\/div>\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"662\" height=\"128\" src=\"https:\/\/t3x.co.uk\/wp-content\/uploads\/2022\/06\/2.jpg\" alt=\"\" class=\"wp-image-585\" srcset=\"https:\/\/t3x.co.uk\/wp-content\/uploads\/2022\/06\/2.jpg 662w, https:\/\/t3x.co.uk\/wp-content\/uploads\/2022\/06\/2-300x58.jpg 300w\" sizes=\"auto, (max-width: 662px) 100vw, 662px\" \/><figcaption>Backup the key somewhere in case you need it later<\/figcaption><\/figure>\n<\/div>\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"547\" height=\"70\" src=\"https:\/\/t3x.co.uk\/wp-content\/uploads\/2022\/06\/2A.jpg\" alt=\"\" class=\"wp-image-586\" srcset=\"https:\/\/t3x.co.uk\/wp-content\/uploads\/2022\/06\/2A.jpg 547w, https:\/\/t3x.co.uk\/wp-content\/uploads\/2022\/06\/2A-300x38.jpg 300w\" sizes=\"auto, (max-width: 547px) 100vw, 547px\" \/><figcaption>Then delete it<\/figcaption><\/figure>\n<\/div>\n\n\n<p>Command to Restore Registry Key<\/p>\n\n\n\n<p>reg import C:\\MSDT\\msdt_backup.reg<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This refers to a means of launching the Microsoft Support Diagnostics Tool (MSDT) which can be via a URI from a malicious source avoiding normal security checks including browser protected mode.<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[5,40],"tags":[46,44,17],"class_list":["post-582","post","type-post","status-publish","format-standard","hentry","category-microsoft","category-threats","tag-security","tag-vulnerabilities","tag-windows"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p3XT9c-9o","_links":{"self":[{"href":"https:\/\/t3x.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/582","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/t3x.co.uk\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/t3x.co.uk\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/t3x.co.uk\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/t3x.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=582"}],"version-history":[{"count":1,"href":"https:\/\/t3x.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/582\/revisions"}],"predecessor-version":[{"id":587,"href":"https:\/\/t3x.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/582\/revisions\/587"}],"wp:attachment":[{"href":"https:\/\/t3x.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=582"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/t3x.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=582"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/t3x.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=582"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}