Junglewise Threat Intelligence

CVE-2024-38178: Microsoft Windows Scripting Engine Memory Corruption Vulnerability

CVE-2024-38178 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2024-08-13

Technologies: Microsoft Windows, Microsoft Windows 11, Microsoft Windows Server 2022 23h2, Microsoft Windows Server 2012 R2, Microsoft Windows Server 2022, Microsoft Windows Server 2019, Microsoft Windows Server 2016, Microsoft Windows 10. Vendors: Microsoft.

Executive brief

Microsoft Windows Scripting Engine contains a memory corruption vulnerability (specifically type confusion) that allows an unauthenticated attacker to achieve remote code execution. Exploitation requires a user to visit a specially crafted URL while using a vulnerable version of the scripting engine.

Affected products

  • Microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 21H2, 22H2, 23H2, 24H2
  • Microsoft Windows Server 2012 R2
  • Microsoft Windows Server 2016
  • Microsoft Windows Server 2019
  • Microsoft Windows Server 2022
  • Microsoft Windows Server 2022 23H2

Timeline

  • 2024-08-13: disclosed
  • 2024-08-13: patched
  • 2024-08-13: kev added: Added to CISA KEV catalog due to evidence of active exploitation.
  • 2024-08-13: exploited

Related threats