Microsoft 365Incident TeardownsRetrospectives

Follina (May–June 2022): Office Documents That Ran Code Without Macros

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from June 2022, written in 2026 with the benefit of hindsight.

In late May 2022, researchers identified a malicious Word document that executed code without macros. The vulnerability it exploited, nicknamed Follina (CVE-2022-30190), was in the Microsoft Support Diagnostic Tool (MSDT). Microsoft released a fix in June 2022.

How it worked

A Word document referenced a remote HTML file. That file used the ms-msdt: URL protocol to launch MSDT with crafted parameters, which executed PowerShell commands. Crucially:

  • Macros weren't needed. Microsoft had been moving to block macros in files from the internet, and Follina bypassed that defense entirely.
  • In some cases (for example, with Rich Text Format files), the exploit triggered in the preview pane without fully opening the document.
  • Protected View offered some protection for Word documents, but not for every variant.

State-linked groups and criminal actors used it in phishing campaigns within days.

Microsoft's response

Microsoft published a workaround — disabling the MSDT URL protocol via a registry change — before releasing patches. Defender added detections and attack surface reduction rules helped block child process creation from Office applications.

Why it mattered

Follina showed attackers adapting quickly to defensive changes. When macros were blocked, they found other ways for Office documents to run code: protocol handlers, container files (ISO, LNK, OneNote) and later other formats.

Lessons in hindsight

  • Attack surface reduction (ASR) rules that block Office apps from creating child processes stop many exploit techniques regardless of the specific vulnerability.
  • Defense in depth beats single controls.
  • Email filtering and detonation (Safe Attachments) catch malicious documents before users open them.
  • Patch quickly when exploitation is active.
follina vulnerabilityFollina2022

More on this story