Follina is a vulnerability in the Microsoft Diagnostic Tool (MSDT) ‘ms-msdt:’ URI that allows a threat actor to embed a link in Microsoft Word documents that could call out to a malicious file server, resulting in code execution by the threat actor.
Researchers at Proofpoint observed Follina being exploited in the wild by the Chinese TA413 hacking group targeting Tibet, and another state-aligned threat group targeting US and EU government agencies. More recently, these researchers also found this vulnerability being used to infect victims with Qbot malware.
Microsoft has released security updates with the June 2022 cumulative Windows Updates to address this vulnerability.