U.S. CISA adds Microsoft Windows MSHTML Platform and Progress WhatsUp Gold bugs to its Known Exploited Vulnerabilities catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-38112 | Windows MSHTML Platform Spoofing Vulnerability Exploited in the Wild (CVE-2024-38112) CVE-2024-38112 is a spoofing flaw (CWE-451) in the Microsoft Windows MSHTML platform, the Windows component used to render web content, including by applications that embed the legacy Internet Explorer engine. It is triggered when a user interacts with attacker-controlled content rendered through MSHTML: the attack requires no privileges, travels over the network, and needs user interaction (UI:R per its CVSS vector), letting an attacker misrepresent critical UI information to the victim. Despite being classified as spoofing, the CVSS impact scores are high across confidentiality, integrity, and availability, and the CVSS base score is 7.5 (High). Any system running the affected Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (21H2, 22H2, 23H2), or Windows Server (2008, 2012, 2016, 2019) releases is affected. Exploitation is confirmed in the wild: Microsoft patched it as an actively exploited zero-day in July 2024, CISA added it to the Known Exploited Vulnerabilities catalog on 2024-07-09, and reporting indicates it had been exploited for over a year before the fix. Do: Apply Microsoft's July 2024 security updates (Patch Tuesday) across all affected Windows 10, Windows 11, and Windows Server versions, prioritizing internet-facing and user workstations given confirmed in-the-wild exploitation and the 84.2% EPSS score. Until patched, remind users to avoid interacting with untrusted web or document content, since exploitation requires user interaction. Track the fix against CISA's KEV catalog deadlines and verify patch status on all endpoints. | 7.5 | 84% | KEV |
| masshundreds of millions of Windows devices (essentially all desktops and servers on the listed Windows 10/11 and Windows Server releases) | |
| CVE-2024-43461 | Windows MSHTML Platform Spoofing Vulnerability Exploited as Zero-Day (CVE-2024-43461) CVE-2024-43461 is a spoofing vulnerability (CWE-451, user interface misrepresentation) in the Windows MSHTML platform that lets attacker-controlled content misrepresent critical UI information to users. The attack is network-delivered and succeeds when a victim interacts with crafted content — such as opening a malicious file or link rendered by MSHTML — so they believe they are handling something benign (public reporting ties the observed campaign to malicious shortcut files that appeared to be ordinary documents). Successful exploitation deceives the user and, given the high confidentiality, integrity, and availability ratings in the CVSS score, can support follow-on compromise, including delivery of attacker-supplied payloads by the Void Banshee APT. Anyone running the affected Windows releases — Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (21H2 through 24H2), and Windows Server 2008, 2012, and 2016 — is in scope. The flaw was exploited in the wild as a zero-day before it was patched in Microsoft's September 2024 updates, was added to CISA's Known Exploited Vulnerabilities catalog on 2024-09-16, and no public PoC is known. Do: Apply Microsoft's September 2024 cumulative Windows security updates to all Windows 10/11 and Windows Server 2008/2012/2016 systems, prioritizing user workstations since exploitation requires user interaction, per the CISA KEV required action. Hunt for Void Banshee APT lures — files or shortcuts whose displayed type does not match their true format — and verify patched build status across the estate, as an earlier related fix was reportedly lost to a code defect and reissued. | 8.8 | 54% | KEV |
| masshundreds of millions to 1+ billion Windows client and server installations (MSHTML is a core component of every listed Windows release) | |
| CVE-2024-6670 | Unauthenticated SQL Injection in Progress WhatsUp Gold (CVE-2024-6670) CVE-2024-6670 is a critical (CVSS 9.8) SQL injection flaw (CWE-89) in Progress Software's WhatsUp Gold network monitoring product, affecting all versions released before 2024.0.0. An unauthenticated attacker can trigger the flaw with crafted requests sent to the product over the network, requiring no privileges or user interaction. Successful exploitation lets the attacker retrieve WhatsUp Gold users' encrypted passwords, which can then potentially be cracked offline to gain valid credentials for further compromise. All organizations running affected releases — especially those with the WhatsUp Gold interface reachable beyond trusted internal networks — are exposed, and the flaw is one of two critical WhatsUp Gold issues Progress fixed in the 2024.0.0 release. CISA added it to the Known Exploited Vulnerabilities catalog on 2024-09-16 with confirmed ransomware use, and EPSS assigns a ~93% probability of exploitation within 30 days, though no public proof-of-concept is catalogued for this flaw. Do: Upgrade to WhatsUp Gold 2024.0.0 or later, the release that fixes this flaw; per CISA's KEV requirement, apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Because the flaw exposes encrypted user passwords, reset WhatsUp Gold credentials after patching and review logs for signs of exploitation, given known ransomware use. | 9.8 | 93% | KEV ransomware |
| large≈10,000–100,000 on-prem deployments worldwide (internet-exposed subset likely in the thousands) |
Full article483 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
September 17, 2024

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft Windows MSHTML Platform and Progress WhatsUp Gold bugs to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added SonicWall SonicOS, ImageMagick and Linux Kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog.
Below are the descriptions for these vulnerabilities:
- CVE-2024-43461 Microsoft Windows MSHTML Platform Spoofing Vulnerability
- CVE-2024-6670 Progress WhatsUp Gold SQL Injection Vulnerability
CVE-2024-43461 – Microsoft this week warned that attackers actively exploited the Windows vulnerability CVE-2024-43461 as a zero-day before July 2024.
The vulnerability CVE-2024-43461 is a Windows MSHTML platform spoofing issue. MSHTML is a platform used by Internet Explorer. Although the browser has been retired, MSHTML remains in Windows and is still used by certain applications.
The ZDI Threat Hunting team discovered a new exploit similar to a previously patched July vulnerability tracked as CVE-2024-38112.
“This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.” reads the advisory published by ZDI. “The specific flaw exists within the way Internet Explorer prompts the user after a file is downloaded. A crafted file name can cause the true file extension to be hidden, misleading the user into believing that the file type is harmless. An attacker can leverage this vulnerability to execute code in the context of the current user.”
Despite reporting it to Microsoft in June, threat actors quickly devised a method to bypass the patch. Though actively used, Microsoft hasn’t labeled it as under attack. The flaw impacts all supported Windows versions.
“Yes. CVE-2024-43461 was exploited as a part of an attack chain relating to CVE-2024-38112, prior to July 2024.” reads the advisory published by Microsoft. “We released a fix for CVE-2024-38112 in our July 2024 security updates which broke this attack chain. See [CVE-2024-38112 – Security Update Guide – Microsoft – Windows MSHTML Platform Spoofing Vulnerability[(https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38112). Customers should both the July 2024 and September 2024 security update to fully protect themselves.”
Patch Tuesday security updates for September 2024 addressed the CVE-2024-43461 vulnerability.
The vulnerability CVE-2024-6670 in WhatsUp Gold is an SQL Injection authentication bypass issue.
An unauthenticated attacker could trigger this vulnerability to retrieve the users encrypted password. The flaw impacts WhatsUp Gold versions released before 2024.0.0.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix this vulnerability by October 7, 2024.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/168505/security/u-s-cisa-microsoft-windows-mshtml-platform-progress-whatsup-gold-bugs-known-exploited-vulnerabilities-catalog.html