Executive brief
The Microsoft Windows MSHTML platform contains a spoofing vulnerability that can lead to a loss of confidentiality and integrity. The flaw is actively exploited in the wild and is associated with improper neutralization of input during web page generation.
Affected products
- Microsoft Windows 10 up to (excluding) 10.0.10240.20796
- Microsoft Windows 11 up to (excluding) 10.0.22631.4317
- Microsoft Windows Server 2016 up to (excluding) 10.0.14393.7428
- Microsoft Windows Server 2019 up to (excluding) 10.0.17763.6414
- Microsoft Windows Server 2022 up to (excluding) 10.0.20348.2762
Timeline
- 2024-10-08: disclosed
- 2024-10-08: patched: Microsoft released security updates.
- 2024-10-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2024-10-08: exploited: Reported as exploited in the wild at the time of publication.