Microsoft confirms second 0-day exploited by Void Banshee APT (CVE-2024-43461)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-38112 | Windows MSHTML Platform Spoofing Vulnerability Exploited in the Wild (CVE-2024-38112) CVE-2024-38112 is a spoofing flaw (CWE-451) in the Microsoft Windows MSHTML platform, the Windows component used to render web content, including by applications that embed the legacy Internet Explorer engine. It is triggered when a user interacts with attacker-controlled content rendered through MSHTML: the attack requires no privileges, travels over the network, and needs user interaction (UI:R per its CVSS vector), letting an attacker misrepresent critical UI information to the victim. Despite being classified as spoofing, the CVSS impact scores are high across confidentiality, integrity, and availability, and the CVSS base score is 7.5 (High). Any system running the affected Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (21H2, 22H2, 23H2), or Windows Server (2008, 2012, 2016, 2019) releases is affected. Exploitation is confirmed in the wild: Microsoft patched it as an actively exploited zero-day in July 2024, CISA added it to the Known Exploited Vulnerabilities catalog on 2024-07-09, and reporting indicates it had been exploited for over a year before the fix. Do: Apply Microsoft's July 2024 security updates (Patch Tuesday) across all affected Windows 10, Windows 11, and Windows Server versions, prioritizing internet-facing and user workstations given confirmed in-the-wild exploitation and the 84.2% EPSS score. Until patched, remind users to avoid interacting with untrusted web or document content, since exploitation requires user interaction. Track the fix against CISA's KEV catalog deadlines and verify patch status on all endpoints. | 7.5 | 84% | KEV |
| masshundreds of millions of Windows devices (essentially all desktops and servers on the listed Windows 10/11 and Windows Server releases) | |
| CVE-2024-43461 | Windows MSHTML Platform Spoofing Vulnerability Exploited as Zero-Day (CVE-2024-43461) CVE-2024-43461 is a spoofing vulnerability (CWE-451, user interface misrepresentation) in the Windows MSHTML platform that lets attacker-controlled content misrepresent critical UI information to users. The attack is network-delivered and succeeds when a victim interacts with crafted content — such as opening a malicious file or link rendered by MSHTML — so they believe they are handling something benign (public reporting ties the observed campaign to malicious shortcut files that appeared to be ordinary documents). Successful exploitation deceives the user and, given the high confidentiality, integrity, and availability ratings in the CVSS score, can support follow-on compromise, including delivery of attacker-supplied payloads by the Void Banshee APT. Anyone running the affected Windows releases — Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (21H2 through 24H2), and Windows Server 2008, 2012, and 2016 — is in scope. The flaw was exploited in the wild as a zero-day before it was patched in Microsoft's September 2024 updates, was added to CISA's Known Exploited Vulnerabilities catalog on 2024-09-16, and no public PoC is known. Do: Apply Microsoft's September 2024 cumulative Windows security updates to all Windows 10/11 and Windows Server 2008/2012/2016 systems, prioritizing user workstations since exploitation requires user interaction, per the CISA KEV required action. Hunt for Void Banshee APT lures — files or shortcuts whose displayed type does not match their true format — and verify patched build status across the estate, as an earlier related fix was reportedly lost to a code defect and reissued. | 8.8 | 54% | KEV |
| masshundreds of millions to 1+ billion Windows client and server installations (MSHTML is a core component of every listed Windows release) |
Full article304 words · extracted from helpnetsecurity.com · click to collapse
CVE-2024-43461, a spoofing vulnerability affecting Windows MSHTML – a software component used by various apps for rendering web pages on Windows – “was exploited as a part of an attack chain relating to CVE-2024-38112, prior to July 2024,” Microsoft has revealed.
The latter vulnerability was patched by the company in July 2024, and threat hunters with Trend Micro’s Zero Day Initiative explained that it had been used by the Void Banshee APT group to deliver Atlantida malware to targets around the world.
The attack chain in action
Based on analyzed samples of malicious files used in the attacks, Check Point researchers concluded that CVE-2024-38112 had likely been exploited in the wild for over a year.
CVE-2024-38112 was leveraged to force a URL file (posing as a PDF file) to be opened with Internet Explorer instead of the Edge browser. The URL lead to a page controlled by the attackers and triggered the download of a HTA file.
The specially crafted HTA (HTML application) file used CVE-2024-43461 to make it appead as a PDF file, hiding its true extension and its malicious nature from the user.
The HTA file carried a script that made use of PowerShell to download and execute an additional script, create a new process for it, download additional trojan loaders and deliver the Atlantida info-stealer.
CVE-2024-43461 fixed
A fix for CVE-2024-43461 was released last week. At the time, Microsoft did not classify it as “exploited”.
On Friday, though, the company confirmed it had been exploited, as part of an attack chain that they “broke” by releasing a fix for CVE-2024-38112 in July.
“Customers should both the July 2024 and September 2024 security update to fully protect themselves,” Microsoft said.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/09/16/cve-2024-43461-exploited/