ZeroHour
Infosecurity Magazinepublished ()ingested Alessandro Mascellino

MHTML Exploited By APT Group Void Banshee

criticalThreat actor exploited in the wildimportance 60CVE-2024-38112

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-38112
Windows MSHTML Platform Spoofing Vulnerability Exploited in the Wild (CVE-2024-38112)

CVE-2024-38112 is a spoofing flaw (CWE-451) in the Microsoft Windows MSHTML platform, the Windows component used to render web content, including by applications that embed the legacy Internet Explorer engine. It is triggered when a user interacts with attacker-controlled content rendered through MSHTML: the attack requires no privileges, travels over the network, and needs user interaction (UI:R per its CVSS vector), letting an attacker misrepresent critical UI information to the victim. Despite being classified as spoofing, the CVSS impact scores are high across confidentiality, integrity, and availability, and the CVSS base score is 7.5 (High). Any system running the affected Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (21H2, 22H2, 23H2), or Windows Server (2008, 2012, 2016, 2019) releases is affected. Exploitation is confirmed in the wild: Microsoft patched it as an actively exploited zero-day in July 2024, CISA added it to the Known Exploited Vulnerabilities catalog on 2024-07-09, and reporting indicates it had been exploited for over a year before the fix.

Do: Apply Microsoft's July 2024 security updates (Patch Tuesday) across all affected Windows 10, Windows 11, and Windows Server versions, prioritizing internet-facing and user workstations given confirmed in-the-wild exploitation and the 84.2% EPSS score. Until patched, remind users to avoid interacting with untrusted web or document content, since exploitation requires user interaction. Track the fix against CISA's KEV catalog deadlines and verify patch status on all endpoints.

7.584% KEV
  • Microsoft Windows 10 1507
  • Microsoft Windows 10 1607
  • Microsoft Windows 10 1809
  • +9 more
masshundreds of millions of Windows devices (essentially all desktops and servers on the listed Windows 10/11 and Windows Server releases)
Full article368 words · extracted from infosecurity-magazine.com · click to collapse

Security experts have uncovered a critical remote code execution (RCE) vulnerability, identified as CVE-2024-38112, within the MHTML protocol handler. 

This vulnerability, dubbed ZDI-CAN-24433, was reported from CVE-2024-38112 to Microsoft upon discovery (and later patched by the tech giant), with evidence suggesting it was actively exploited by the advanced persistent threat (APT) group Void Banshee. 

Known for targeting North American, European and Southeast Asian regions, Void Banshee leveraged CVE-2024-38112 as part of a sophisticated attack chain designed to steal sensitive information and achieve financial gain.

The attack culminated in the deployment of the Atlantida stealer, a malware variant initially detected in January 2024. Throughout the year, variations of this campaign intensified, incorporating CVE-2024-38112 to compromise systems. 

By exploiting the MHTML vulnerability through internet shortcut (.URL) files, Void Banshee manipulated disabled instances of Internet Explorer on Windows systems, circumventing security measures and executing malicious payloads such as HTML Applications (HTA).

In response to this threat, Trend Micro monitored the evolving campaign in mid-May 2024, leveraging internal and external telemetry to track Void Banshee's tactics, techniques and procedures (TTPs). 

The attackers exploited not only the MHTML protocol but also Microsoft protocol handlers and URI schemes, exploiting remnants of Internet Explorer present in modern Windows versions despite its official discontinuation and disabling.

The severity of CVE-2024-38112 prompted Microsoft to issue a patch during its July 2024 Patch Tuesday cycle, which effectively unregistered the MHTML handler from Internet Explorer. This critical step mitigates the risk posed by this vulnerability, preventing further exploitation through internet shortcut files.

Read more about the latest Patch Tuesday fixes: Microsoft Fixes Four Zero-Days in July Patch Tuesday

According to Trend Micro, the incident underscores ongoing concerns regarding the exploitation of legacy components like Internet Explorer, which despite being phased out, remain latent vulnerabilities in modern Windows environments. 

"Since services such as IE have a large attack surface and no longer receive patches, it represents a serious security concern to Windows users," Trend Micro said.

"When faced with uncertain intrusions, behaviors and routines, organizations should assume that their system is already compromised or breached and work to immediately isolate affected data or toolchains. With a broader perspective and rapid response, organizations can address breaches and protect [their] remaining systems."

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/cve-2024-38112-exploited-void/