Last seen December 29, 2025

CVE-2022-30190 Remote Code Execution Vulnerability affecting Windows

Evidence indicates that Windows is affected by remote code execution. Exploitation evidence is classified as confirmed in the wild.

Technical Severity
High severity
Lifecycle Status

STABLE

What Happened

Evidence indicates that Windows is affected by remote code execution. Exploitation evidence is classified as confirmed in the wild.

Why This Matters

The evidence matters to defenders using Windows because it could let an attacker run code in affected environments.

Recommended Action

Apply updates per vendor instructions. Confirm whether Windows is present in your environment and review the affected configuration.

Exposure

Recommended Response
First Seen

Dec 29, 2025 05:30

Last Seen

Dec 29, 2025 05:30

Exploitation status: CONFIRMED_IN_THE_WILD

Primary entities:

Microsoft Windows Data Leakage Prompt Injection Remote Code Execution CVE-2022-30190

Authoritative Intelligence

CVE CVE-2022-30190 Incident identifier
NVD CVSS 7.8 HIGH NVD
FIRST EPSS 0.992 99.9 pct
CWE NVD-CWE-noinfo Weakness classification

Provider evidence: NVD, CISA KEV, FIRST EPSS

EPSS is a vulnerability exploitation probability signal, not proof that your environment is exposed. CISA KEV means known exploitation of the vulnerability, not that your system was exploited.

Timeline

  • Incident first seen
    Dec 29, 2025 05:30

    BugSkan first recorded this incident.

  • Defending AI Systems Against Prompt Injection Attacks - wiz.io
    Dec 29, 2025 05:30

    wiz.io · Vulnerability

Sources

Defending AI Systems Against Prompt Injection Attacks - wiz.io

wiz.io · Dec 29, 2025 05:30

Prompt injection attacks manipulate AI systems, particularly Large Language Models (LLMs), by overriding their intended instructions through malicious input, leading to sensitive data leakage, unauthorized actions, or corrupted outputs. A real-world example involved a phishing campaign leveraging hidden text-based prompt injection to bypass AI defenses, coupled with the exploitation of CVE-2022-30190 (Follina) for remote code execution.

Open publisher source

Watchlist Match

Want personalized relevance?

Create an account to see which incidents overlap with the technologies you monitor.

← Back to incident intelligence