CVE-2024-38112

Vulnerability updated 21 days ago (2024-09-16T19:17:58.719Z)
Download STIX
Preview STIX
CVE-2024-38112 is a software vulnerability discovered in the MSHTML (Trident) engine, primarily used by the now-retired Internet Explorer browser. Despite this, newer Windows 10 and Windows 11 systems, where Edge is the default browser, are also susceptible to attacks exploiting this flaw. This vulnerability was first publicly disclosed via Microsoft's Security Update Guide in July 2024, illustrating the potential for platform spoofing. The Advanced Persistent Threat (APT) group known as Void Banshee exploited this vulnerability, targeting victims across North America, Europe, and Southeast Asia. The group's use of CVE-2024-38112 was detailed in a blog post published by Trend Micro on July 15, 2024. This provided further insight into how the APT leveraged the flaw, highlighting the severity and widespread implications of the issue. In response to the discovery and exploitation of CVE-2024-38112, Microsoft and Trend Micro collaborated closely to address the issue. Their efforts culminated in the release of an official patch by Microsoft on July 9, 2024. This patch mitigates the risk posed by the vulnerability, protecting users from potential platform spoofing and subsequent cyberattacks.
Description last updated: 2024-09-16T19:15:37.007Z
What's your take? (Question 1 of 2)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Microsoft
Vulnerability
Windows
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the CVE-2024-38112 Vulnerability was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
Securityaffairs
21 days ago
DARKReading
21 days ago
Securityaffairs
21 days ago
DARKReading
a month ago
Securityaffairs
2 months ago
Securityaffairs
2 months ago
DARKReading
2 months ago
Securityaffairs
3 months ago
Securityaffairs
3 months ago
Securityaffairs
3 months ago
Securityaffairs
3 months ago
Securityaffairs
3 months ago
DARKReading
3 months ago
InfoSecurity-magazine
3 months ago
Checkpoint
3 months ago
BankInfoSecurity
3 months ago
DARKReading
3 months ago
Securityaffairs
3 months ago
InfoSecurity-magazine
3 months ago
Securityaffairs
3 months ago