CVE-2024-43461
KEVmass1Windows MSHTML Platform Spoofing Vulnerability Exploited as Zero-Day (CVE-2024-43461)
CISA: Microsoft Windows MSHTML Platform Spoofing Vulnerability
CVE-2024-43461 is a spoofing vulnerability (CWE-451, user interface misrepresentation) in the Windows MSHTML platform that lets attacker-controlled content misrepresent critical UI information to users. The attack is network-delivered and succeeds when a victim interacts with crafted content — such as opening a malicious file or link rendered by MSHTML — so they believe they are handling something benign (public reporting ties the observed campaign to malicious shortcut files that appeared to be ordinary documents). Successful exploitation deceives the user and, given the high confidentiality, integrity, and availability ratings in the CVSS score, can support follow-on compromise, including delivery of attacker-supplied payloads by the Void Banshee APT. Anyone running the affected Windows releases — Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (21H2 through 24H2), and Windows Server 2008, 2012, and 2016 — is in scope. The flaw was exploited in the wild as a zero-day before it was patched in Microsoft's September 2024 updates, was added to CISA's Known Exploited Vulnerabilities catalog on 2024-09-16, and no public PoC is known.
What to do: Apply Microsoft's September 2024 cumulative Windows security updates to all Windows 10/11 and Windows Server 2008/2012/2016 systems, prioritizing user workstations since exploitation requires user interaction, per the CISA KEV required action. Hunt for Void Banshee APT lures — files or shortcuts whose displayed type does not match their true format — and verify patched build status across the estate, as an earlier related fix was reportedly lost to a code defect and reissued.
| Microsoft Windows 10 1507 | 1507 |
| Microsoft Windows 10 1607 | 1607 |
| Microsoft Windows 10 1809 | 1809 |
| Microsoft Windows 10 21H2 | 21H2 |
| Microsoft Windows 10 22H2 | 22H2 |
| Microsoft Windows 11 21H2 | 21H2 |
| Microsoft Windows 11 22H2 | 22H2 |
| Microsoft Windows 11 23H2 | 23H2 |
| Microsoft Windows 11 24H2 | 24H2 |
| Microsoft Windows Server 2008 | 2008 |
| Microsoft Windows Server 2012 | 2012 |
| Microsoft Windows Server 2016 | 2016 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Windows MSHTML Platform Spoofing Vulnerability
- Affected
- Microsoft Windows
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 21h2, windows 11 22h2, windows 11 23h2, windows 11 24h2, windows server 2008, windows server 2012, windows server 2016
- Weakness
- CWE-451
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H