Junglewise Threat Intelligence

CVE-2024-38112: Microsoft Windows MSHTML Platform Spoofing Vulnerability

CVE-2024-38112 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2024-07-09

Technologies: Microsoft Windows Server, Microsoft Windows, Microsoft Windows 11, Microsoft Windows 10. Vendors: Microsoft.

Executive brief

A spoofing vulnerability exists in the Microsoft Windows MSHTML platform that allows for user interface misrepresentation. The flaw has been observed being exploited in the wild and requires user interaction to succeed.

Affected products

  • Microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 21H2, 22H2, 23H2
  • Microsoft Windows Server 2008, 2012 R2, 2016, 2019, 2022, 23H2
  • Microsoft MSHTML Platform

Timeline

  • 2024-07-09: disclosed
  • 2024-07-09: patched
  • 2024-07-09: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-07-09: exploited: Reported as exploited in the wild at time of publication.

Related threats