Skip to main content

Update Windows now to patch this critical Microsoft Word exploit

Microsoft has rolled out security updates as part of its June 2022 Windows updates to address a serious security bug that has targeted programs including Microsoft Word.

The Windows zero-day vulnerability is known as Follina (CVE-2022-30190) by security researchers and is “actively exploited in ongoing attacks,” according to Bleeping Computer.

Recommended Videos

https://twitter.com/wdormann/status/1537075968568877057?s=20&t=kiqSGqhiv31Vo6kLKFdLlg

Microsoft recommends those running Windows 7 or higher update their systems as soon as possible. However, if you have automatic updates set up, you won’t have to take any actions.

Researchers became aware of the security flaw in late May; however, Microsoft appeared to not closely address the situation, offering manual Command prompt workarounds for the issue rather than a software patch.

Vulnerability Analyst Will Dormann noted that the June update rolling out even seems to be misdated, as if it became available in May rather than now.

The first Follina attacks might have started as early as mid-April, “with sextortion threats and invitations to Sputnik Radio interviews as baits,” Bleeping Computer added.

Security researcher CrazymanArmy of Shadow Chaser Group told the publication that Microsoft’s security team rejected his submission at that time as not a “security-related issue.”

The zero-day vulnerability is able to grant hackers access to the Microsoft Support Diagnostic Tool (MSDT), according to the security company Proofpoint. This tool is commonly associated with Microsoft Office and Microsoft Word. From there, hackers are able to access computer back ends, granting them permission to install programs, create new user accounts, and manipulate data on a device.

The first documented Follina attack was traced to a Chinese TA413 hacking group, aimed at the Tibetan diaspora. Follow-up attacks were phishing scams aimed at U.S. and E.U. government agencies. The most recent attacks are connected to the TA570 Qbot affiliate, which is conducting phishing scams with Qbot malware, the publication added.

Fionna Agomuoh
Fionna Agomuoh is a Computing Writer at Digital Trends. She covers a range of topics in the computing space, including…
Windows 11 users outsmart Microsoft once again with new local account trick
A screenshot of the Windows 11 Microsoft Account setup page

A newly discovered trick allows Windows 11 users to bypass Microsoft’s online account requirement during setup, raising questions around user control and privacy. The workaround, shared by X user @witherornot1337, lets users set up Windows 11 with a local account instead of being forced to log in with a Microsoft account.

This follows previous similar methods, highlighting an ongoing cat-and-mouse game between Microsoft and privacy-conscious users. Microsoft has been increasingly pushing online accounts as a mandatory requirement for Windows 11, particularly in Home and Pro editions. This change has frustrated many users who prefer local accounts for greater privacy and independence from Microsoft’s ecosystem.

Read more
I hope Microsoft adds these 6 things to the next major Windows Update
Windows 11 logo on a laptop.

Windows 11 updates have a bit of a reputation, from slowing Intel's newest desktop processors to breaking games. Despite the occasional hiccup, we still look forward with cautious optimism.

Despite the occasional rough patch, Microsoft continues to evolve the OS, and each update feels like a chance for a new beginning. While Microsoft hasn't confirmed anything yet, the rumor mill is buzzing with what comes next, and I'm starting to feel excited. The talk of new features suggests fixes for long-standing annoyances, productivity boosts, and quality-of-life improvements worth waiting for.
What's coming to Windows in 2025?

Read more
Microsoft could make account-free Windows 11 installs a thing of the past
Windows 11 logo on a laptop.

The offline Windows 11 install looks like it could officially be a thing of the past. 

Microsoft is officially shutting the door on local accounts during Windows 11 setup, confirming that all new installations, Home and Pro alike, will now require a Microsoft account. 

Read more