ZeroHour

CVE-2024-38178

KEVmass1

Unauthenticated RCE via Memory Corruption in Microsoft Windows Scripting Engine

CISA: Microsoft Windows Scripting Engine Memory Corruption Vulnerability

CVSS 3.1
7.5 high
EPSS
41%p99
Published
()
KEV added
AI analysis

CVE-2024-38178 is a memory corruption flaw (CWE-843 type confusion) in the Microsoft Windows Scripting Engine that allows an unauthenticated attacker to execute arbitrary code. Exploitation is triggered when a user is lured into opening a specially crafted URL, so no prior authentication or network access to the target is required. A successful attack gains remote code execution, typically in the context of the fooled user's privileges. Any supported Microsoft Windows system with the scripting engine is affected, per CISA's listing of 'Microsoft Windows'. The vulnerability is confirmed to be exploited in the wild: CISA added it to the KEV catalog on 2024-08-13, coinciding with Microsoft's August 2024 Patch Tuesday, and EPSS assigns a high 41.4% probability of exploitation in the next 30 days.

What to do: Apply Microsoft's August 2024 Windows cumulative security updates immediately, prioritizing internet-facing and high-value systems, and verify patch levels against the KBs released 2024-08-13. As interim mitigation, limit user exposure to untrusted links and consider restricting or disabling legacy scripting/IE-mode rendering where business needs allow. No public PoC is known, but KEV listing confirms active exploitation, so hunt for anomalous process spawns from browsing/link-opening activity and apply CISA's required action of vendor mitigations or discontinuing use.

Affected
Microsoft Windows (Scripting Engine)CISA lists 'Microsoft Windows' without enumerating ranges; affected Windows releases are those covered by Microsoft's August 2024 security updates
Estimated exposure
masshundreds of millions of Windows devices worldwide — Windows runs on an estimated ~1.4 billion devices/users and the scripting engine is a core component present across affected Windows releases until the August 2024 updates are applied, making the exposed base effectively the unpatched…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Scripting Engine Memory Corruption Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 21h2, windows 11 22h2, windows 11 23h2, windows 11 24h2, windows server 2012, windows server 2016, windows server 2019
Weakness
CWE-843
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news