Executive brief
A spoofing vulnerability exists in the Microsoft Windows MSHTML platform that allows for user interface misrepresentation. The flaw has been observed being exploited in the wild and requires user interaction to succeed.
Affected products
- Microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 21H2, 22H2, 23H2
- Microsoft Windows Server 2008, 2012 R2, 2016, 2019, 2022, 23H2
- Microsoft MSHTML Platform
Timeline
- 2024-07-09: disclosed
- 2024-07-09: patched
- 2024-07-09: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-07-09: exploited: Reported as exploited in the wild at time of publication.