Last seen December 29, 2025

CVE-2022-30190 Remote Code Execution Vulnerability affecting AI systems

Prompt injection attacks manipulate AI systems, particularly Large Language Models (LLMs), by overriding their intended instructions through malicious input, leading to sensitive data leakage, unauthorized actions, or corrupted outputs. A real-world example involved a phishing campaign leveraging hidden text-based prompt injection to bypass AI defenses, coupled with the exploitation of CVE-2022-30190 (Follina) for remote code execution.

Technical Severity
High severity
Lifecycle Status

STABLE

What Happened

Prompt injection attacks manipulate AI systems, particularly Large Language Models (LLMs), by overriding their intended instructions through malicious input, leading to sensitive data leakage, unauthorized actions, or corrupted outputs. A real-world example involved a phishing campaign leveraging hidden text-based prompt injection to bypass AI defenses, coupled with the exploitation of CVE-2022-30190 (Follina) for remote code execution.

Why This Matters

The evidence matters to defenders using AI systems because it could let an attacker run code in affected environments.

Recommended Action

Confirm whether llm is present in your environment, compare your versions against the report, and apply available vendor patches or mitigations.

Exposure

My Interests Exposure

Exposure unknown

Recommended Response
Last Seen

Dec 29, 2025 05:30

Exposure reason: This incident does not currently match a technology in My Interests.

Exploitation status: CONFIRMED_IN_THE_WILD

Primary entities:

AI systemsLarge Language ModelsData LeakagePrompt InjectionRemote Code ExecutionAgainst Prompt Injection

Authoritative Intelligence

CVE CVE-2022-30190 Incident identifier

EPSS is a vulnerability exploitation probability signal, not proof that your environment is exposed. CISA KEV means known exploitation of the vulnerability, not that your system was exploited.

Public GitHub References

Search GitHub for public repositories that mention this CVE. BugSkan only lists repository metadata as a defensive awareness signal โ€” it does not fetch or display exploit code.

CVE-2022-30190: 6 public repository references found.

JMousqueton/PoC-CVE-2022-30190

Possible public PoC reference

POC CVE-2022-30190 : CVE 0-day MS Offic RCE aka msdt follina

158 stars ยท Python

Open repository
onecloudemoji/CVE-2022-30190

Possible public PoC reference

CVE-2022-30190 Follina POC

104 stars ยท HTML

Open repository
Noxtal/follina

Possible public PoC reference

All about CVE-2022-30190, aka follina, that is a RCE vulnerability that affects Microsoft Support Diagnostic Tools (MSDT) on Office apps such as Word. This is a very simple POC, feel free to check the sources below for more threat intelligence.

21 stars ยท Python

Open repository
dwisiswant0/gollina

Possible public PoC reference

Follina MS-MSDT 0-day MS Office RCE (CVE-2022-30190) PoC in Go

17 stars ยท Go

Open repository
drgreenthumb93/CVE-2022-30190-follina

Possible public PoC reference

Just another PoC for the new MSDT-Exploit

8 stars ยท HTML

Open repository
sudoaza/CVE-2022-30190

Possible public PoC reference

MS-MSDT Follina CVE-2022-30190 PoC document generator

7 stars ยท HTML

Open repository

A public PoC or exploit-related repository means weaponization material may exist in the open. It does not prove your environment was targeted.

Timeline

  • Incident first seen
    Dec 29, 2025 05:30

    BugSkan first recorded this incident.

  • Defending AI Systems Against Prompt Injection Attacks - wiz.io
    Dec 29, 2025 05:30

    wiz.io ยท Vulnerability

Sources

Defending AI Systems Against Prompt Injection Attacks - wiz.io

wiz.io ยท Dec 29, 2025 05:30

Prompt injection attacks manipulate AI systems, particularly Large Language Models (LLMs), by overriding their intended instructions through malicious input, leading to sensitive data leakage, unauthorized actions, or corrupted outputs. A real-world example involved a phishing campaign leveraging hidden text-based prompt injection to bypass AI defenses, coupled with the exploitation of CVE-2022-30190 (Follina) for remote code execution.

Open publisher source

Other BugSkan incidents that share identifiers, products, or vendors with this report.

My Interests Match

Want personalized relevance?

Create an account to see which incidents overlap with your interests.

โ† Back to incident intelligence