MSDT RCE DogWalk (CVE-2022-34713)

Опубликовано: 22 Февраль 2026
на канале: Alexander Leonov
253
1

Remote Code Execution in Microsoft Windows Support Diagnostic Tool (#MSDT) (CVE-2022-34713), dubbed DogWalk. The only Urgent level vulnerability. The Microsoft Support Diagnostic Tool (MSDT) is a service in Microsoft Windows that allows #Microsoft technical support agents to analyze diagnostic data remotely for troubleshooting purposes. DogWalk vulnerability allows code execution when MSDT is called using the URL protocol from a calling application, typically Microsoft Word. There is an element of social engineering to this as a threat actor would need to convince a user to click a link or open a document. Exploitability Assessment: Exploitation in the wild detected. The existence of a public exploit is mentioned in Microsoft CVSS Temporal Score (Functional Exploit). But it is not yet available in public exploit packs. DogWalk is similar to MSDT RCE Follina (CVE-2022-30190), which made some hype in May of this year. It’s not clear if this vulnerability is the result of a failed patch or something new.

Telegram: https://t.me/avleonovcom/1031
Blogpost: https://avleonov.com/2022/08/23/micro...