Msdt.exe !!top!! Direct
Most users interact with the diagnostic tool through graphical interfaces, often without realizing they are using msdt.exe . For example, when you right-click a network adapter and select "Diagnose," you are initiating a diagnostic wizard driven by this tool.
Even before Follina, the vulnerability (originally reported in 2020 but patched in 2022) allowed attackers to execute commands via .diagcab files. If a user downloaded and opened a malicious diagnostic cabinet file, msdt.exe would run code outside of its intended sandbox. msdt.exe