ZeroHour

CVE-2024-30040

KEVmass1

Actively Exploited Security Feature Bypass in Microsoft Windows MSHTML Platform

CISA: Microsoft Windows MSHTML Platform Security Feature Bypass Vulnerability

CVSS 3.1
8.8 high
EPSS
4%p90
Published
()
KEV added
AI analysis

CVE-2024-30040 is a high-severity (CVSS 8.8) security feature bypass in the Windows MSHTML platform, the HTML-rendering engine component embedded in Internet Explorer and many Windows applications. A remote attacker can trigger it by persuading a user to open or render specially crafted content, since the attack requires user interaction but no privileges or special conditions (AV:N/AC:L/PR:N/UI:R). Successful exploitation defeats an intended Windows security feature, and the high confidentiality, integrity, and availability impact ratings indicate it can enable significant compromise when chained with other techniques. All supported Windows 10 and Windows 11 client releases (1507 through 22H2, and 21H2 through 23H2, respectively) plus Windows Server 2016, 2019, 2022, and 2022 23H2 are affected. The flaw is being actively exploited in the wild — it was added to CISA's KEV catalog on 2024-05-14 and was one of two zero-days fixed in Microsoft's May 2024 Patch Tuesday — though no public proof-of-concept is known and EPSS estimates a 3.9% chance of exploitation in the next 30 days (90th percentile).

What to do: Apply the May 2024 Patch Tuesday cumulative updates (released 2024-05-14) for Windows 10, Windows 11, and Windows Server as soon as possible; the flaw is under active exploitation and listed in CISA KEV, so prioritize endpoints and servers that render untrusted documents or HTML content. Confirm via patch reporting that the May 2024 cumulative update is installed on all assets, and in the interim caution users against opening unsolicited files and links, since exploitation requires user interaction.

Affected
microsoft Windows 101507, 1607, 1809, 21H2, 22H2
microsoft Windows 1121H2, 22H2, 23H2
microsoft Windows Server2016, 2019, 2022, 2022 23H2
Estimated exposure
mass≈1 billion+ Windows installations (MSHTML is a core component of every supported Windows 10/11 and Windows Server release) — MSHTML ships with all supported Windows 10/11 clients and Windows Server versions, and Microsoft reports over a billion active Windows devices worldwide, so the exposed base is effectively the entire installed Windows estate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows MSHTML Platform Security Feature Bypass Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 21h2, windows 11 22h2, windows 11 23h2, windows server 2016, windows server 2019, windows server 2022, windows server 2022 23h2
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news