Search

Microsoft Releases a Windows Update to Fix 'Follina' Vulnerability Actively Exploited by Hackers

Shortly after the vulnerability became public, China-backed hackers were able to exploit it to target some Tibetan users.

Advertisement
Highlights
  • Microsoft has made the update for users on Windows 7 and later
  • Windows update fixes the issue impacting MSDT component
  • Microsoft was first made aware about the vulnerability in April
Microsoft Releases a Windows Update to Fix 'Follina' Vulnerability Actively Exploited by Hackers

Microsoft has urged Windows users to install the update

Photo Credit: Reuters

Microsoft has finally released a Windows security fix for the vulnerability that has actively been exploited by hackers. The issue, which was named "Follina" by security researchers, was publicly disclosed last month, though it was initially reported to the Redmond company in April. It enables attackers to hack Windows PCs using a maliciously crafted Microsoft Word document. The security update is available for users on Windows 7 and later. Microsoft has urged users to install the update "as soon as possible" to restrict attackers from gaining access to their systems.

Windows users should install the update by going to the Settings. The update has also been released for systems that are configured to receive automatic updates, Microsoft said in an update to its security advisory.

"Microsoft strongly recommends that customers install the updates to be fully protected from the vulnerability," the company noted.

As reported last month, the security issue, which has been tracked as CVE-2022-30190, was disclosed on Twitter by Tokyo-based cybersecurity researcher team Nao_sec. It initially appeared to be impacting Microsoft Office, though Microsoft acknowledged that the flaw was related to Microsoft Diagnostic Tool (MSDT) that comes preloaded on Windows operating system.

Attackers would be able to exploit the vulnerability by executing PowerShell commands and eventually gain control of the MSDT.

Shortly after it became public, the severe vulnerability was found to be exploited by China-based hackers by using malicious Word documents to Tibetan users. When the documents are accessed, the attackers would be able to leverage the exploit to gain MSDT access and run tasks including installation of certain programs or creation of new user accounts.

As reported by Bleeping Computer, the latest update doesn't restrict Microsoft Office from loading Windows URI handlers without user interactions. It, however, limits attackers to get the control of MSDT by executing PowerShell commands.

The security update is available to all users who have a system running Windows 7 or later. Windows 10 versions have received it as KB5014699, while the update is available as KB5014697 on Windows 11 systems.


This week on Orbital, the Gadgets 360 podcast, we discuss the Surface Pro 8, Go 3, Duo 2, and Laptop Studio — as Microsoft sets a vision for Windows 11 hardware. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

 
Show Full Article
Please wait...
Advertisement

Related Stories

Popular Mobile Brands
  1. Vivo T4 5G Set to Launch in India Soon; to Be Available on Flipkart
  2. Vivo X200 Ultra Confirmed to Launch in April; Could Arrive With Vivo X200s
  3. iQOO Z10 Showcased in Two Colourways
  4. Sony WF-C710N TWS Earphones With Up to 30 Hours Total Battery Life Launched
  5. Nothing Adds Camera Capture Feature to Phone 3a's Essential Space
  6. Vivo Vision With Apple Vision Pro-Inspired Design Unveiled in China
  7. Samsung Galaxy Z Flip 7, Galaxy Z Fold 7 Leaked Accessories Hint at Design
  8. IPL 2025 Live Streaming for Free: How to Watch RR vs KKR IPL Match Online?
  9. Nintendo Switch 2 Outlook by Goldman Sachs Drives Shares
  1. Vivo Y300t Confirmed to Get 6,500mAh Battery; to Launch Alongside Vivo Y300 Pro+ on March 31
  2. Google’s Gemini 2.5 Pro AI Model Launched; Tops Leaderboard, Outperforms OpenAI’s o3 Mini
  3. Apple iOS 19 Leaked Mockups Suggest ‘Glassy’, VisionOS-Inspired Design
  4. Oppo's Book-Style Foldable Tablet Design Spotted in Patent Document
  5. Vivo T4 5G Confirmed to Launch in India Soon; to Be Available on Flipkart
  6. Sony WF-C710N TWS Earphones With ANC, Up to 30 Hours Total Battery Life Launched
  7. Samsung Galaxy Z Flip 7 Leaked Case Renders Suggest Design; Galaxy Z Fold 7 Protective Glass Surfaces Online
  8. Tecno Camon 40 Series to Get OS Updates Up to Android 18, 5 Years of Security Patches
  9. ChatGPT Improves Photo Editing Feature, Lets Users Create Charts for Work
  10. Nintendo Switch 2 Outlook by Goldman Sachs Drives Shares
Gadgets 360 is available in
Download Our Apps
App Store App Store
Available in Hindi
App Store
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.
Trending Products »
Latest Tech News »