CVE-2022-30190 Remote Code Execution Vulnerability affecting AI systems
Prompt injection attacks manipulate AI systems, particularly Large Language Models (LLMs), by overriding their intended instructions through malicious input, leading to sensitive data leakage, unauthorized actions, or corrupted outputs. A real-world example involved a phishing campaign leveraging hidden text-based prompt injection to bypass AI defenses, coupled with the exploitation of CVE-2022-30190 (Follina) for remote code execution.
What Happened
Prompt injection attacks manipulate AI systems, particularly Large Language Models (LLMs), by overriding their intended instructions through malicious input, leading to sensitive data leakage, unauthorized actions, or corrupted outputs. A real-world example involved a phishing campaign leveraging hidden text-based prompt injection to bypass AI defenses, coupled with the exploitation of CVE-2022-30190 (Follina) for remote code execution.
Why This Matters
The evidence matters to defenders using AI systems because it could let an attacker run code in affected environments.
Recommended Action
Confirm whether llm is present in your environment, compare your versions against the report, and apply available vendor patches or mitigations.
Exposure
Exposure unknown
Dec 29, 2025 05:30
Exposure reason: This incident does not currently match a technology in My Interests.
Exploitation status: CONFIRMED_IN_THE_WILD
Primary entities:
Authoritative Intelligence
Public GitHub References
Search GitHub for public repositories that mention this CVE. BugSkan only lists repository metadata as a defensive awareness signal โ it does not fetch or display exploit code.
CVE-2022-30190: 6 public repository references found.
Possible public PoC reference
POC CVE-2022-30190 : CVE 0-day MS Offic RCE aka msdt follina
158 stars ยท Python
Open repositoryPossible public PoC reference
CVE-2022-30190 Follina POC
104 stars ยท HTML
Open repositoryPossible public PoC reference
All about CVE-2022-30190, aka follina, that is a RCE vulnerability that affects Microsoft Support Diagnostic Tools (MSDT) on Office apps such as Word. This is a very simple POC, feel free to check the sources below for more threat intelligence.
21 stars ยท Python
Open repositoryPossible public PoC reference
Follina MS-MSDT 0-day MS Office RCE (CVE-2022-30190) PoC in Go
17 stars ยท Go
Open repositoryPossible public PoC reference
Just another PoC for the new MSDT-Exploit
8 stars ยท HTML
Open repositoryPossible public PoC reference
MS-MSDT Follina CVE-2022-30190 PoC document generator
7 stars ยท HTML
Open repositoryA public PoC or exploit-related repository means weaponization material may exist in the open. It does not prove your environment was targeted.
Timeline
-
Incident first seen
Dec 29, 2025 05:30BugSkan first recorded this incident.
-
Defending AI Systems Against Prompt Injection Attacks - wiz.io
Dec 29, 2025 05:30wiz.io ยท Vulnerability
Sources
wiz.io ยท Dec 29, 2025 05:30
Prompt injection attacks manipulate AI systems, particularly Large Language Models (LLMs), by overriding their intended instructions through malicious input, leading to sensitive data leakage, unauthorized actions, or corrupted outputs. A real-world example involved a phishing campaign leveraging hidden text-based prompt injection to bypass AI defenses, coupled with the exploitation of CVE-2022-30190 (Follina) for remote code execution.
Open publisher sourceRelated Incidents
Other BugSkan incidents that share identifiers, products, or vendors with this report.
My Interests Match
Create an account to see which incidents overlap with your interests.