ZeroHour

CVE-2024-38112

KEVmass1

Windows MSHTML Platform Spoofing Vulnerability Exploited in the Wild (CVE-2024-38112)

CISA: Microsoft Windows MSHTML Platform Spoofing Vulnerability

CVSS 3.1
7.5 high
EPSS
84%p100
Published
()
KEV added
AI analysis

CVE-2024-38112 is a spoofing flaw (CWE-451) in the Microsoft Windows MSHTML platform, the Windows component used to render web content, including by applications that embed the legacy Internet Explorer engine. It is triggered when a user interacts with attacker-controlled content rendered through MSHTML: the attack requires no privileges, travels over the network, and needs user interaction (UI:R per its CVSS vector), letting an attacker misrepresent critical UI information to the victim. Despite being classified as spoofing, the CVSS impact scores are high across confidentiality, integrity, and availability, and the CVSS base score is 7.5 (High). Any system running the affected Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (21H2, 22H2, 23H2), or Windows Server (2008, 2012, 2016, 2019) releases is affected. Exploitation is confirmed in the wild: Microsoft patched it as an actively exploited zero-day in July 2024, CISA added it to the Known Exploited Vulnerabilities catalog on 2024-07-09, and reporting indicates it had been exploited for over a year before the fix.

What to do: Apply Microsoft's July 2024 security updates (Patch Tuesday) across all affected Windows 10, Windows 11, and Windows Server versions, prioritizing internet-facing and user workstations given confirmed in-the-wild exploitation and the 84.2% EPSS score. Until patched, remind users to avoid interacting with untrusted web or document content, since exploitation requires user interaction. Track the fix against CISA's KEV catalog deadlines and verify patch status on all endpoints.

Affected
Microsoft Windows 101507
Microsoft Windows 101607
Microsoft Windows 101809
Microsoft Windows 1021H2
Microsoft Windows 1022H2
Microsoft Windows 1121H2
Microsoft Windows 1122H2
Microsoft Windows 1123H2
Microsoft Windows Server2008
Microsoft Windows Server2012
Microsoft Windows Server2016
Microsoft Windows Server2019
Estimated exposure
masshundreds of millions of Windows devices (essentially all desktops and servers on the listed Windows 10/11 and Windows Server releases) — The affected component (MSHTML) ships with all supported Windows 10/11 client and Windows Server releases, so exposure scales with the enormous installed base of those OS versions rather than with an optional add-on or plugin; exact counts…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows MSHTML Platform Spoofing Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 21h2, windows 11 22h2, windows 11 23h2, windows server 2008, windows server 2012, windows server 2016, windows server 2019
Weakness
CWE-451
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news