Products
Features
YouTube Video Summarizer
Summarize YouTube videos
Web & PDF Highlighter
Highlight web pages & PDFs
Chat with PDF
Ask any PDF questions with AI
Ask AI Clone
Chat with your highlights & memories
Audio Transcriber
Transcribe audio files to text
Glasp Reader
Read and highlight articles
Kindle Highlight Export
Export your Kindle highlights
Idea Hatch
Hatch ideas from your highlights
Integrations
Obsidian Plugin
Notion Integration
Pocket Integration
Instapaper Integration
Medium Integration
Readwise Integration
Snipd Integration
Hypothesis Integration
Apps & Extensions
Chrome Extension
Safari Extension
Edge Add-ons
Firefox Add-ons
iOS App
Android App
Discover
Discover
Ideas
Discover new ideas and insights
Articles
Curated articles and insights
Books
Book recommendations by great minds
Posts
Essays and notes from readers
Quotes
Inspiring quotes collection
Videos
Curated videos and summaries
Explore Glasp
Glasp Newsletter
Weekly insights and updates
Glasp Talk
Interview series with great minds
Glasp Blog
Latest news and articles
Glasp Use Cases
Learn how others use Glasp
Build & Support
Glasp API
Access Glasp's API for developers
MCP Connector
Connect Glasp to Claude & ChatGPT
Community
Glasp Reddit Community
Students
Student discount and benefits
FAQs
Frequently Asked Questions
AboutPricing
DashboardLog inSign up

Windows Zero Day: MSDT Follina Exploit Demonstration

June 13, 2022
by
The PC Security Channel
YouTube video player
Windows Zero Day: MSDT Follina Exploit Demonstration

TL;DR

A vulnerability in Microsoft's support diagnostic tool allows attackers to remotely execute code on a victim's system, potentially leading to malware infection and other malicious activities.

Transcript

all of this without you doing anything so we're going to try this command should be pretty straightforward creating a docx here and remember this is not something that needs to happen on your system this is something that would typically happen in an attacker system this video is brought to you by crowdsec a free open source intrusion detection sys... Read More

Key Insights

  • 👻 The vulnerability in Microsoft's support diagnostic tool allows attackers to remotely execute code on victims' systems without their knowledge or interaction.
  • 👨‍🦱 Disabling the msdt URL protocol and applying the necessary patch can prevent exploitation of this vulnerability.
  • 😒 Attackers often use Word documents as the delivery method for the malicious payload, leveraging social engineering techniques.
  • 👨‍💼 This vulnerability poses a significant threat to both individual users and businesses, as it can result in malware infections and potential data breaches.
  • ❓ Cybercriminals frequently exploit similar vulnerabilities to profit from infecting systems and deploying malicious payloads.
  • 😄 The demonstrated exploit process using a Python script highlights the ease with which attackers can create and distribute malicious documents.
  • ✳️ Organizations should prioritize patching vulnerabilities promptly to mitigate the risk of exploitation.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: What is the vulnerability in Microsoft's support diagnostic tool?

The vulnerability is a remote code execution exploit that allows attackers to execute code on a victim's system without their knowledge or interaction.

Q: How can users protect themselves from this vulnerability?

Users can disable the msdt URL protocol and apply the necessary patch to prevent exploitation of this vulnerability.

Q: How do attackers typically deliver the malicious payload?

Attackers often use a Word document containing the payload as an email attachment. When the victim opens the document, the payload is executed.

Q: Can this vulnerability be used to deliver other types of malware?

Yes, this vulnerability can be used to deliver various types of malware, including remote access tools, ransomware, and other sophisticated malicious programs.

Summary & Key Takeaways

  • Attackers are exploiting a remote code execution vulnerability in Microsoft's support diagnostic tool to deliver malware payloads to unsuspecting users' systems.

  • To prevent exploitation, users should disable the msdt URL protocol and apply the necessary patch.

  • The video demonstrates the exploit process using a Python script that creates a Word document containing the malicious payload, showcasing the potential risks.


Read in Other Languages (beta)

English

Share This Summary 📚

Summarize YouTube Videos and Get Video Transcripts with 1-Click

Download browser extensions on:

Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator

Explore More Summaries from The PC Security Channel 📚

Security Talk 6: Bleeping Computer sued for a negative review and more thumbnail
Security Talk 6: Bleeping Computer sued for a negative review and more
The PC Security Channel
Avast vs Ransomware thumbnail
Avast vs Ransomware
The PC Security Channel
Beware the flashing skull | Petya Ransomware thumbnail
Beware the flashing skull | Petya Ransomware
The PC Security Channel
MGM & Defcon Venue hack: BlackCat Ransomware thumbnail
MGM & Defcon Venue hack: BlackCat Ransomware
The PC Security Channel
DynA-Crypt Ransomware | feat. Karsten from G Data thumbnail
DynA-Crypt Ransomware | feat. Karsten from G Data
The PC Security Channel
NordVPN Hacked! How secure is VPN Really? thumbnail
NordVPN Hacked! How secure is VPN Really?
The PC Security Channel

Summarize YouTube Videos and Get Video Transcripts with 1-Click

Download browser extensions on:

Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator

Apps & Extensions

  • Chrome Extension
  • Safari Extension
  • Edge Add-ons
  • Firefox Add-ons
  • iOS App
  • Android App

Key Features

  • YouTube Video Summarizer
  • Web & PDF Summarizer
  • Web & PDF Highlighter
  • Chat with PDF
  • Ask AI Clone
  • Audio Transcriber
  • Glasp Reader
  • Kindle Highlight Export
  • Idea Hatch

Integrations

  • Obsidian Plugin
  • Notion Integration
  • Pocket Integration
  • Instapaper Integration
  • Medium Integration
  • Readwise Integration
  • Snipd Integration
  • Hypothesis Integration

More Features

  • APIs
  • MCP Connector
  • Blog & Post
  • Embed Links
  • Image Highlight
  • Personality Test
  • Quote Shots

Company

  • About us
  • Blog
  • Community
  • FAQs
  • Job Board
  • Newsletter
  • Pricing
Terms

•

Privacy

•

Guidelines

© 2026 Glasp Inc. All rights reserved.