Follina — a Microsoft Office code execution vulnerability

Kevin Beaumont
DoublePulsar
Published in
9 min readMay 29, 2022

--

Two days ago, on May 27th 2022, Nao_sec identified an odd looking Word document in the wild, uploaded from an IP address in Belarus. This turned out to be a zero day vulnerability in Office and/or Windows.

--

--