Skip to main content

Update Windows now to patch this critical Microsoft Word exploit

Microsoft has rolled out security updates as part of its June 2022 Windows updates to address a serious security bug that has targeted programs including Microsoft Word.

The Windows zero-day vulnerability is known as Follina (CVE-2022-30190) by security researchers and is “actively exploited in ongoing attacks,” according to Bleeping Computer.

Recommended Videos

https://twitter.com/wdormann/status/1537075968568877057?s=20&t=kiqSGqhiv31Vo6kLKFdLlg

Microsoft recommends those running Windows 7 or higher update their systems as soon as possible. However, if you have automatic updates set up, you won’t have to take any actions.

Researchers became aware of the security flaw in late May; however, Microsoft appeared to not closely address the situation, offering manual Command prompt workarounds for the issue rather than a software patch.

Vulnerability Analyst Will Dormann noted that the June update rolling out even seems to be misdated, as if it became available in May rather than now.

The first Follina attacks might have started as early as mid-April, “with sextortion threats and invitations to Sputnik Radio interviews as baits,” Bleeping Computer added.

Security researcher CrazymanArmy of Shadow Chaser Group told the publication that Microsoft’s security team rejected his submission at that time as not a “security-related issue.”

The zero-day vulnerability is able to grant hackers access to the Microsoft Support Diagnostic Tool (MSDT), according to the security company Proofpoint. This tool is commonly associated with Microsoft Office and Microsoft Word. From there, hackers are able to access computer back ends, granting them permission to install programs, create new user accounts, and manipulate data on a device.

The first documented Follina attack was traced to a Chinese TA413 hacking group, aimed at the Tibetan diaspora. Follow-up attacks were phishing scams aimed at U.S. and E.U. government agencies. The most recent attacks are connected to the TA570 Qbot affiliate, which is conducting phishing scams with Qbot malware, the publication added.

Fionna Agomuoh
Fionna Agomuoh is a Computing Writer at Digital Trends. She covers a range of topics in the computing space, including…
Nearly six months later, you can finally try out Windows 11 Recall
Recall promotional image.

After a tumultuous initial reaction and months of reworking, Microsoft is finally releasing the first preview of its controversial Recall feature today. If you're a Windows Insider with a Qualcomm Copilot+ PC, you can install a new build of Windows 11 that includes both Recall and Click to Do.

If you're not part of the Windows Insider Program but you want to try out this feature, it's pretty easy to sign up on the Microsoft website. Recall was first announced back before any of the Copilot+ PCs were released and was meant to be available at launch, but an outcry of privacy and security concerns forced Microsoft to delay it.

Read more
The Windows 11 24H2 update is causing even more problems
Windows 11 logo on a laptop.

The Windows 11 24H2 update had already been giving users a real headache with problems such as bugs for visual layouts and flaws for certain wallpaper apps. And now, as Microsoft confirms in a support document, some people without administrative privileges can't change the time zone in the Date & Time view, among myriad other issues related to the important Windows 11 update.

A Feedback Hub post also reports a time issue after exiting Sleep Mode, specifically after about one out of every five overnight sleep cycles. There is also a report that the time is not syncing correctly following daylight saving time. Put differently, the update doesn't break the time zone, but only affects the toggle or makes it very difficult to modify it.

Read more
Windows 11 takes a break on updates until 2025
Windows 11 logo on a laptop.

Microsoft has confirmed that it is going on holiday break for Windows 11 updates, indicating that any major software features won’t be released until January 2025.

The company rolled out its latest software update, OS Build 26100.2314 on November 12, and it largely addressed security issues. It also detailed that there won’t be any preview updates released in December 2024, outside of monthly security releases.

Read more