What Was Follina? The Diagnostic Tool That Ran the Attack
The tool Windows ships to diagnose problems was the thing running the attack.
What was Follina?
Follina, catalogued as CVE-2022-30190, was a way to run code on a Windows machine from a Microsoft Office document without any macro. It worked by abusing the ms-msdt URL scheme, which hands control to the Microsoft Support Diagnostic Tool, the utility that normally gathers logs and system information when you ask Windows for help. A document could invoke that handler and feed it a command, and the command ran.
Macros are the thing everyone has been trained to distrust in Office documents, the thing that pops a yellow warning bar and asks you to enable content. Follina needed none of it. There was no macro to enable, so there was no warning to ignore.
The preview pane was enough
It got worse than a document you had to open. Because the exploit could be triggered through the way Office loads a document's remote template, a version built as an RTF file would fire from the Explorer preview pane, the moment the file was selected in a folder, before anyone double-clicked anything. Selecting the file to look at it was enough to run the code. For a stretch that spring, the safe move was to make sure your file browser was not even showing you a preview.
The timeline is the uncomfortable part
A researcher reported the technique to Microsoft's Security Response Center in April 2022. Microsoft closed the case, saying it was not a security-related issue. There the matter sat.
It became public on 27 May 2022, when a research group called nao_sec found a malicious document using the technique in the wild, uploaded from Belarus. Only then, with working attacks circulating and every security team on earth now aware of it, did it get a CVE and, on 14 June 2022, an actual patch. The gap between a researcher handing Microsoft the bug and Microsoft treating it as a bug was the length of the whole story.
Where the name comes from
From Kevin Beaumont, who analysed the public sample and noticed it referenced the number 0438. That is the telephone area code for Follina, a small town in the province of Treviso in northern Italy. The name stuck faster than the fix arrived, which is often how it goes: the community needs a word for the thing before the vendor is willing to admit the thing has a number.
Why it mattered
Follina was not the most damaging vulnerability of its year, but it was one of the most instructive. It showed that the trusted-document threat model built around macros had a side door in a diagnostic handler nobody had thought about. It showed that preview-pane execution turns "don't open suspicious files" into inadequate advice. And it showed, again, that the interval between a quiet report and a public patch can be the interval in which everyone else is exposed.
The tool that diagnoses the problem was the problem.
Further reading
- nao_sec — the original 27 May 2022 thread identifying the in-the-wild sample.
- Kevin Beaumont — Follina — a Microsoft Office code execution vulnerability, DoublePulsar, May 2022.
- Microsoft Security Response Center — guidance and the CVE-2022-30190 advisory, May–June 2022.
- CISA — alert on CVE-2022-30190 and mitigation guidance, 2022.
EXHIBIT 0034 — FOLLINA
We put it on a shirt. An antique binaural stethoscope, drawn as an engraving, coiled on a surface with a small tag tied to the tube reading ms-msdt: and 0438.
Callouts: THE DIAGNOSTIC TOOL RAN THE CODE. NO MACRO. THE PREVIEW PANE WAS ENOUGH. REPORTED IN APRIL, CALLED NOT A SECURITY ISSUE. NAMED FOR AREA CODE 0438.
The tool that diagnoses the problem was the problem.
That's the whole idea.