{"cveID":"CVE-2022-34713","vendorProject":"Microsoft","product":"Windows","vulnerabilityName":"Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability","dateAdded":"2022-08-09","shortDescription":"A remote code execution vulnerability exists when Microsoft Windows MSDT is called using the URL protocol from a calling application.","requiredAction":"Apply updates per vendor instructions.","dueDate":"2022-08-30","knownRansomwareCampaignUse":"Unknown","notes":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-34713;  https://nvd.nist.gov/vuln/detail/CVE-2022-34713","cwes":[],"year":2022,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2022-34713","technique":"T1566","technique_name_at_mapping":"Phishing","mapping_type":"exploitation_technique","capability_group":"code_execution","comments":"This vulnerability is exploited when a user is tricked by an adversary to open a maliciously crafted file either via an email or malicious website. Once the user opens the file, an adversary gains the ability to execute arbitrary code the next time the victim restarts their computer and logs in.","references":["https://www.makeuseof.com/microsoft-patches-dogwalk-zero-day/","https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-34713"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2022-34713","technique":"T1059","technique_name_at_mapping":"Command and Scripting Interpreter","mapping_type":"secondary_impact","capability_group":"code_execution","comments":"This vulnerability is exploited when a user is tricked by an adversary to open a maliciously crafted file. Once the user opens the file, an adversary gains the ability to execute arbitrary code the next time the victim restarts their computer and logs in. ","references":["https://www.makeuseof.com/microsoft-patches-dogwalk-zero-day/","https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-34713"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2022-34713","technique":"T1204.002","technique_name_at_mapping":"Malicious File","mapping_type":"primary_impact","capability_group":"code_execution","comments":"This vulnerability is exploited when a user is tricked by an adversary to open a maliciously crafted file either via an email or malicious website. Once the user opens the file, an adversary gains the ability to execute arbitrary code the next time the victim restarts their computer and logs in.","references":["https://www.makeuseof.com/microsoft-patches-dogwalk-zero-day/","https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-34713"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1059","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Command and Scripting Interpreter","name_at_mapping":"Command and Scripting Interpreter","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":95,"has_detection_strategy":true},{"id":"T1204.002","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Malicious File","name_at_mapping":"Malicious File","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":39,"has_detection_strategy":true},{"id":"T1566","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Phishing","name_at_mapping":"Phishing","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":14,"has_detection_strategy":true}],"mapping_types":["exploitation_technique","primary_impact","secondary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"full","sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-23 05:47 UTC","_attack_version":"19.2"}