ZeroHour
Security Affairspublished ()ingested @securityaffairs

Security Affairs newsletter Round 481 by Pierluigi Paganini

criticalRansomwareimportance 60CVE-2024-38112

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-38112
Windows MSHTML Platform Spoofing Vulnerability Exploited in the Wild (CVE-2024-38112)

CVE-2024-38112 is a spoofing flaw (CWE-451) in the Microsoft Windows MSHTML platform, the Windows component used to render web content, including by applications that embed the legacy Internet Explorer engine. It is triggered when a user interacts with attacker-controlled content rendered through MSHTML: the attack requires no privileges, travels over the network, and needs user interaction (UI:R per its CVSS vector), letting an attacker misrepresent critical UI information to the victim. Despite being classified as spoofing, the CVSS impact scores are high across confidentiality, integrity, and availability, and the CVSS base score is 7.5 (High). Any system running the affected Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (21H2, 22H2, 23H2), or Windows Server (2008, 2012, 2016, 2019) releases is affected. Exploitation is confirmed in the wild: Microsoft patched it as an actively exploited zero-day in July 2024, CISA added it to the Known Exploited Vulnerabilities catalog on 2024-07-09, and reporting indicates it had been exploited for over a year before the fix.

Do: Apply Microsoft's July 2024 security updates (Patch Tuesday) across all affected Windows 10, Windows 11, and Windows Server versions, prioritizing internet-facing and user workstations given confirmed in-the-wild exploitation and the 84.2% EPSS score. Until patched, remind users to avoid interacting with untrusted web or document content, since exploitation requires user interaction. Track the fix against CISA's KEV catalog deadlines and verify patch status on all endpoints.

7.584% KEV
  • Microsoft Windows 10 1507
  • Microsoft Windows 10 1607
  • Microsoft Windows 10 1809
  • +9 more
masshundreds of millions of Windows devices (essentially all desktops and servers on the listed Windows 10/11 and Windows Server releases)
Full article360 words · extracted from securityaffairs.com · click to collapse

A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.

International Press – Newsletter

Cybercrime  

AT&T Paid a Hacker $370,000 to Delete Stolen Phone Records

Data breach exposes millions of mSpy spyware customers  

Threat actors misusing Quick Assist in social engineering attacks leading to ransomware  

FIN7 Reboot | Cybercrime Gang Enhances Ops with New EDR Bypasses and Automated Attacks   

Interpol operation nabs 300 with links to West African cyber fraud  

Disney Investigating Hacker Group’s Data Theft Claims

Two Foreign Nationals Plead Guilty to Participation in LockBit Ransomware Group  

Teenage suspect in MGM Resorts hack arrested in Britain   

Malware

Hardening of HardBit   

10,000 Victims a Day: Infostealer Garden of Low-Hanging Fruit

This Meeting Should Have Been an Email  

MuddyWater replaces Atera by custom MuddyRot implant in a recent campaign

Fake AWS Packages Ship Command and Control Malware In JPEG Files      

HotPage: Story of a signed, vulnerable, ad-injecting driver  

Hacking

How to tell if your online accounts have been hacked 

It’s never been easier for the cops to break into your phone          

CVE-2024-38112: Void Banshee Targets Windows Users Through Zombie Internet Explorer in Zero-Day Attacks  

Hacker Leaks Thousands of Microsoft and Nokia Employee Details  

SAPwned: SAP AI vulnerabilities expose customers’ cloud environments and private AI artifacts  

Over 400,000 Life360 user phone numbers leaked via unsecured API

Likely eCrime Actor Uses Filenames Capitalizing on July 19, 2024, Falcon Sensor Content Issues in Operation Targeting LATAM-Based CrowdStrike Customers  

Intelligence and Information Warfare 

French military intelligence is worried about increasing foreign interference

Kaspersky Lab Closing U.S. Division; Laying Off Workers  

Italian government agencies and companies in the target of a Chinese APT   

Cybersecurity  

Banks in Singapore to phase out one-time passwords in 3 months

FBI Gains Access to Suspected Trump Shooter’s Password Locked Phone  

It’s never been easier for the cops to break into your phone  

Faulty CrowdStrike Update Crashes Windows Systems, Impacting Businesses Worldwide

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)



you might also like

leave a comment

Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/166006/breaking-news/security-affairs-newsletter-round-481-by-pierluigi-paganini-international-edition.html