- Description
- Windows MSHTML Platform Spoofing Vulnerability
- Source
- secure@microsoft.com
- NVD status
- Analyzed
CVSS 3.1
- Type
- Primary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity
- HIGH
Data from CISA
- Vulnerability name
- Microsoft Windows MSHTML Platform Spoofing Vulnerability
- Exploit added on
- Sep 16, 2024
- Exploit action due
- Oct 7, 2024
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- nvd@nist.gov
- NVD-CWE-Other
- secure@microsoft.com
- CWE-451
- Hype score
- Not currently trending
Windows vulnerability abused braille “spaces” in zero-day attacks A recently fixed "Windows MSHTML spoofing vulnerability" tracked under CVE-2024-43461 is now marked as previously exploited after it was used in attacks by the Void Banshee APT hacking g... https://t.co/X9hLRjorci
@SecurityAid
3 Jan 2025
23 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Patch out for CVE-2024-49041, an Edge vulnerability we disclosed to @Microsoft. This finding came as a result of our previous disclosure of CVE-2024-43461 and CVE-2024-38112. A case of narrow patching in Internet Explorer vs. Microsoft Edge! #infosec https://t.co/lKtnGhtxpJ
@gothburz
10 Dec 2024
2753 Impressions
5 Retweets
15 Likes
3 Bookmarks
0 Replies
0 Quotes
CVE-2024-43461, a critical flaw in MSHTML, allows attackers to execute arbitrary code remotely. With over 10% of Windows 10/11 systems lacking endpoint protection, it's vital to update and secure your systems against these threats. https://t.co/f7oC3fDNuR
@Shift6Security
7 Nov 2024
54 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Actively exploited CVE : CVE-2024-43461
@transilienceai
25 Oct 2024
13 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Actively exploited CVE : CVE-2024-43461
@transilienceai
23 Oct 2024
8 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Actively exploited CVE : CVE-2024-43461
@transilienceai
20 Oct 2024
7 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Actively exploited CVE : CVE-2024-43461
@transilienceai
10 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x64:*",
"vulnerable": true,
"matchCriteriaId": "85DD5735-7C22-4A98-B404-08FEF44A640F",
"versionEndExcluding": "10.0.10240.20766"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x86:*",
"vulnerable": true,
"matchCriteriaId": "83550045-529B-4968-A543-C9D298C0F31D",
"versionEndExcluding": "10.0.10240.20766"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*",
"vulnerable": true,
"matchCriteriaId": "90027BBC-56AF-4F14-A118-53BBA694A0CD",
"versionEndExcluding": "10.0.14393.7336"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*",
"vulnerable": true,
"matchCriteriaId": "DFB6CBF4-DA4A-4743-B8A1-3E41FCBEEBEC",
"versionEndExcluding": "10.0.14393.7336"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3A9450F3-BE07-4F9B-9C2B-29208AB91A9C",
"versionEndExcluding": "10.0.17763.6293"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "30C7FEB1-00AE-42A6-BBAA-A30081BD4A83",
"versionEndExcluding": "10.0.19044.4894"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:arm64:*",
"vulnerable": true,
"matchCriteriaId": "6FBDC450-FB5A-469C-8D38-9586CE5A6F48",
"versionEndExcluding": "10.0.19045.4894"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x64:*",
"vulnerable": true,
"matchCriteriaId": "6A08D353-356F-4BB0-A43F-15EBD6E2FB83",
"versionEndExcluding": "10.0.19045.4894"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x86:*",
"vulnerable": true,
"matchCriteriaId": "13DBA791-6F77-4DA1-8BF4-BA7C299C6188",
"versionEndExcluding": "10.0.19045.4894"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_21h2:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FF161E1C-AF7E-4F75-86BA-8479D0BA8086",
"versionEndExcluding": "10.0.22000.3197"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "10708C4D-4596-4089-8DDB-5479DE084F64",
"versionEndExcluding": "10.0.22621.4169"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*",
"vulnerable": true,
"matchCriteriaId": "76AB8812-9BA5-415B-A6B1-C5AD065D3382",
"versionEndExcluding": "10.0.22621.4169"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*",
"vulnerable": true,
"matchCriteriaId": "5EFBBCCD-A83C-4D06-BBF0-1A4E5C9F0283",
"versionEndExcluding": "10.0.22631.4169"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "889E645C-92D6-422B-A89B-05D6774B7543",
"versionEndExcluding": "10.0.26100.1742"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x64:*",
"vulnerable": true,
"matchCriteriaId": "2127D10C-B6F3-4C1D-B9AA-5D78513CC996"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x86:*",
"vulnerable": true,
"matchCriteriaId": "AB425562-C0A0-452E-AABE-F70522F15E1A"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2008:r2:*:*:*:*:*:x64:*",
"vulnerable": true,
"matchCriteriaId": "B7674920-AE12-4A25-BE57-34AEDDA74D76"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:x64:*",
"vulnerable": true,
"matchCriteriaId": "F73D1308-DB13-4B6C-A66F-5542FDCA749C"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:x64:*",
"vulnerable": true,
"matchCriteriaId": "8968BAC8-A1DB-4F88-89F8-4BE47919C247"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A6291C92-7D32-4CC2-B601-FAF5B70F3BFD",
"versionEndExcluding": "10.0.14393.7336"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BD2C9E88-C858-4B3D-A8C5-251DD6B69FD6",
"versionEndExcluding": "10.0.17763.6293"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4399F533-0094-43CF-872E-FC8E4A21A904",
"versionEndExcluding": "10.0.20348.2700"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FCB2DB55-B6D1-4D28-802F-D300BE10E9A0",
"versionEndExcluding": "10.0.25398.1128"
}
],
"operator": "OR"
}
]
}
]