
let’s play with a ZERO-DAY vulnerability “follina”
Source: YouTube · NetworkChuck · published Jun 1, 2022 · 21:10
This video examines the "Follina" (CVE-2022-30190) zero-day vulnerability, a critical remote code execution exploit in Microsoft Word that bypasses macro security to execute malicious commands 0:10.
Key Takeaways:
• The vulnerability exploits the Microsoft Support Diagnostic Tool (MSDT) via a Word document, allowing attackers to run arbitrary PowerShell code without needing enabled macros 2:54.
• NetworkChuck demonstrates how to build a secure testing environment using VirtualBox with Kali Linux and Windows 11 to analyze the threat safely 9:24.
• Using a Python script from researcher John Hammond, the presenter shows how the exploit works by launching a calculator and establishing a reverse shell to gain full system control 19:19.
• Despite Windows Defender potentially flagging the attack, the best mitigation strategy remains user awareness and avoiding suspicious email attachments 20:28.
Understanding and practicing these exploits in isolated labs is crucial for developing effective defenses against emerging cyber threats 20:43.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
All right. So fingers crossed.
Let's see if this works. This is CDE 20 22 3 0 1 9 0. AKA Felina. Now I don't
normally do videos like this, but this was just too crazy. What you
just saw was a zero day vulnerability, a hack that has no fix no. Patch. Yeah. It's kind of
crazy. Uh, there's honestly, no patch available right now. And
it's a remote code execution, right? So that's Hey, the crown
jewel that's high critical. Severity. Like John said, this
vulnerability is brand new, pretty scary high severity. Like the hacking researching community
just became aware of this over the weekend. So we have to look at it. Right?
In fact, I want you to play with this. I'm gonna walk you through how to set
up this vulnerability in your own lab. So you can see what this is like a
current zero day that ha…