Microsoft Windows Support Diagnostic Tool (MSDT) Vulnerability (CVE-2022-30190)

Canon Medical Systems Security Advisory

Overview:
It was announced that there is security vulnerability that affects Microsoft Windows Support Diagnostic Tool (MSDT). MSDT is a service in Microsoft Windows that allows Microsoft technical support agents to analyze diagnostic data remotely for troubleshooting purposes. A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word.
REF:https://msrc-blog.microsoft.com/2022/05/30/guidance-for-cve-2022-30190-microsoft-support-diagnostic-tool-vulnerability/

Vulnerability Overview:
A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability by specially crafted file can run arbitrary code with the privileges of the calling application. The attacker can then install programs, view, change, or delete data, or create new accounts in the context allowed by the user’s rights.

Possible Affected Canon Medical Systems Products:
Canon Medical Imaging Products are not affected Because no Office software such as Word.

Resolution:
None

Contact Us