Executive brief
The Microsoft Windows MSHTML Platform contains a spoofing vulnerability due to the misrepresentation of critical user interface information. Attackers can exploit this to spoof web pages, and the flaw has been observed being used in conjunction with CVE-2024-38112 in active attacks.
Affected products
- Microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 21H2, 22H2, 23H2, 24H2
- Microsoft Windows Server 2008 SP2, R2
- Microsoft Windows Server 2012 R2
- Microsoft Windows Server 2016 All versions
- Microsoft Windows Server 2019 All versions
- Microsoft Windows Server 2022 All versions
- Microsoft MSHTML Platform
Timeline
- 2024-09-10: disclosed: Initial disclosure by Microsoft and NVD publication.
- 2024-09-16: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.
- 2024-09-16: exploited: Confirmed as exploited in the wild.
- 2024-09-16: patched: Patch information referenced in MSRC update guide.