Security Affairs newsletter Round 481 by Pierluigi Paganini
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-38112 | Windows MSHTML Platform Spoofing Vulnerability Exploited in the Wild (CVE-2024-38112) CVE-2024-38112 is a spoofing flaw (CWE-451) in the Microsoft Windows MSHTML platform, the Windows component used to render web content, including by applications that embed the legacy Internet Explorer engine. It is triggered when a user interacts with attacker-controlled content rendered through MSHTML: the attack requires no privileges, travels over the network, and needs user interaction (UI:R per its CVSS vector), letting an attacker misrepresent critical UI information to the victim. Despite being classified as spoofing, the CVSS impact scores are high across confidentiality, integrity, and availability, and the CVSS base score is 7.5 (High). Any system running the affected Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (21H2, 22H2, 23H2), or Windows Server (2008, 2012, 2016, 2019) releases is affected. Exploitation is confirmed in the wild: Microsoft patched it as an actively exploited zero-day in July 2024, CISA added it to the Known Exploited Vulnerabilities catalog on 2024-07-09, and reporting indicates it had been exploited for over a year before the fix. Do: Apply Microsoft's July 2024 security updates (Patch Tuesday) across all affected Windows 10, Windows 11, and Windows Server versions, prioritizing internet-facing and user workstations given confirmed in-the-wild exploitation and the 84.2% EPSS score. Until patched, remind users to avoid interacting with untrusted web or document content, since exploitation requires user interaction. Track the fix against CISA's KEV catalog deadlines and verify patch status on all endpoints. | 7.5 | 84% | KEV |
| masshundreds of millions of Windows devices (essentially all desktops and servers on the listed Windows 10/11 and Windows Server releases) |
Full article360 words · extracted from securityaffairs.com · click to collapse

A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free in your email box.
Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.
International Press – Newsletter
Cybercrime
AT&T Paid a Hacker $370,000 to Delete Stolen Phone Records
Data breach exposes millions of mSpy spyware customers
Threat actors misusing Quick Assist in social engineering attacks leading to ransomware
FIN7 Reboot | Cybercrime Gang Enhances Ops with New EDR Bypasses and Automated Attacks
Interpol operation nabs 300 with links to West African cyber fraud
Disney Investigating Hacker Group’s Data Theft Claims
Two Foreign Nationals Plead Guilty to Participation in LockBit Ransomware Group
Teenage suspect in MGM Resorts hack arrested in Britain
Malware
10,000 Victims a Day: Infostealer Garden of Low-Hanging Fruit
This Meeting Should Have Been an Email
MuddyWater replaces Atera by custom MuddyRot implant in a recent campaign
Fake AWS Packages Ship Command and Control Malware In JPEG Files
HotPage: Story of a signed, vulnerable, ad-injecting driver
Hacking
How to tell if your online accounts have been hacked
It’s never been easier for the cops to break into your phone
Hacker Leaks Thousands of Microsoft and Nokia Employee Details
SAPwned: SAP AI vulnerabilities expose customers’ cloud environments and private AI artifacts
Over 400,000 Life360 user phone numbers leaked via unsecured API
Intelligence and Information Warfare
French military intelligence is worried about increasing foreign interference
Kaspersky Lab Closing U.S. Division; Laying Off Workers
Italian government agencies and companies in the target of a Chinese APT
Cybersecurity
Banks in Singapore to phase out one-time passwords in 3 months
FBI Gains Access to Suspected Trump Shooter’s Password Locked Phone
It’s never been easier for the cops to break into your phone
Faulty CrowdStrike Update Crashes Windows Systems, Impacting Businesses Worldwide
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)
you might also like
leave a comment
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/166006/breaking-news/security-affairs-newsletter-round-481-by-pierluigi-paganini-international-edition.html