CVE-2024-43461

Published Sep 10, 2024

Last updated 5 months ago

Overview

Description
Windows MSHTML Platform Spoofing Vulnerability
Source
secure@microsoft.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity
HIGH

Known exploits

Data from CISA

Vulnerability name
Microsoft Windows MSHTML Platform Spoofing Vulnerability
Exploit added on
Sep 16, 2024
Exploit action due
Oct 7, 2024
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weaknesses

nvd@nist.gov
NVD-CWE-Other
secure@microsoft.com
CWE-451

Social media

Hype score
Not currently trending
  1. Windows vulnerability abused braille “spaces” in zero-day attacks A recently fixed "Windows MSHTML spoofing vulnerability" tracked under CVE-2024-43461 is now marked as previously exploited after it was used in attacks by the Void Banshee APT hacking g... https://t.co/X9hLRjorci

    @SecurityAid

    3 Jan 2025

    23 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Patch out for CVE-2024-49041, an Edge vulnerability we disclosed to @Microsoft. This finding came as a result of our previous disclosure of CVE-2024-43461 and CVE-2024-38112. A case of narrow patching in Internet Explorer vs. Microsoft Edge! #infosec https://t.co/lKtnGhtxpJ

    @gothburz

    10 Dec 2024

    2753 Impressions

    5 Retweets

    15 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  3. CVE-2024-43461, a critical flaw in MSHTML, allows attackers to execute arbitrary code remotely. With over 10% of Windows 10/11 systems lacking endpoint protection, it's vital to update and secure your systems against these threats. https://t.co/f7oC3fDNuR

    @Shift6Security

    7 Nov 2024

    54 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Actively exploited CVE : CVE-2024-43461

    @transilienceai

    25 Oct 2024

    13 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  5. Actively exploited CVE : CVE-2024-43461

    @transilienceai

    23 Oct 2024

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  6. Actively exploited CVE : CVE-2024-43461

    @transilienceai

    20 Oct 2024

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  7. Actively exploited CVE : CVE-2024-43461

    @transilienceai

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

Configurations