// the find
JohnHammond/msdt-follina
Codebase to generate an msdt-follina payload
A one-shot PoC from John Hammond that builds a malicious .docx exploiting the MS-MSDT 'Follina' remote code execution bug (CVE-2022-30190), paired with a built-in HTTP server to stage the payload. It's for security researchers and red teamers who want to understand or demo the exploit chain, not for anyone looking for a maintained tool.
Single-file Python script with the full chain visible end to end — doc templating, HTML payload, and local HTTP server in one place, so you can actually trace how the exploit fires instead of trusting a black box. The reverse-shell mode goes beyond the usual calc.exe pop and shows a real post-exploitation path. It shipped within days of the public disclosure, which has real historical value for anyone studying how 0-days get weaponized.
Dead project: last push June 2022, right when Microsoft patched the bug, so it's useless against any current target and exists purely as an artifact. Ships a compiled nc64.exe binary directly in the repo — that's going to trip AV/GitHub scanning and is a bad habit to normalize in a public PoC. The reverse-shell path drops that binary onto the victim and never cleans it up, which the README itself flags as sloppy. No tests, no CI, no error handling beyond the happy path — it's a demo script, not something to build tooling on top of.