Overview
- Description
- Windows MSHTML Platform Security Feature Bypass Vulnerability
- Source
- secure@microsoft.com
- NVD status
- Analyzed
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity
- HIGH
Known exploits
Data from CISA
- Vulnerability name
- Microsoft Windows MSHTML Platform Security Feature Bypass Vulnerability
- Exploit added on
- May 14, 2024
- Exploit action due
- Jun 4, 2024
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Weaknesses
- nvd@nist.gov
- NVD-CWE-noinfo
- secure@microsoft.com
- CWE-20
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "37A197DA-6408-4B32-A3C5-4ED9F8D9B100", "versionEndExcluding": "10.0.10240.20651" }, { "criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*", "vulnerable": true, "matchCriteriaId": "208A4966-0B4A-44BD-A94E-D432529D4A7A", "versionEndExcluding": "10.0.14393.6981" }, { "criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*", "vulnerable": true, "matchCriteriaId": "D0993DA2-43E8-4E09-A8FE-9D4EC48A881D", "versionEndExcluding": "10.0.14393.6981" }, { "criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7CA2824B-BEA1-438D-A606-65BF5C85AF19", "versionEndExcluding": "10.0.17763.5820" }, { "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "64DEDA09-D9D3-4974-A4C1-36D2A7C27916", "versionEndExcluding": "10.0.19044.4412" }, { "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1EAF4860-124C-4A1B-AF4B-12C676E545DC", "versionEndExcluding": "10.0.19045.4412" }, { "criteria": "cpe:2.3:o:microsoft:windows_11_21h2:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8C65169A-BEF8-4C27-8F3C-F30401DFDB71", "versionEndExcluding": "10.0.22000.2960" }, { "criteria": "cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D96D1BF2-D11D-4355-A9E8-7F89485772D3", "versionEndExcluding": "10.0.22621.3593" }, { "criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "44D7840D-388C-46D8-9782-A49FE9D54704", "versionEndExcluding": "10.0.22631.3593" }, { "criteria": "cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7B922822-E4BC-4538-9E88-EDA645062A44", "versionEndExcluding": "10.0.14393.6981" }, { "criteria": "cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4A3B72F9-A2EA-4C74-98B5-3543A98B9098", "versionEndExcluding": "10.0.17763.5820" }, { "criteria": "cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "31EAEF01-DD3A-4DDC-8D12-2AE71CADD6BD", "versionEndExcluding": "10.0.20348.2458" }, { "criteria": "cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7510F630-1C49-4F21-A814-2406F94CA5C7", "versionEndExcluding": "10.0.25398.887" } ], "operator": "OR" } ] } ]