Security News > 2024 > July > Zero-day patched by Microsoft has been exploited by attackers for over a year (CVE-2024-38112)

Zero-day patched by Microsoft has been exploited by attackers for over a year (CVE-2024-38112)
2024-07-10 12:35

CVE-2024-38112, a spoofing vulnerability in Windows MSHTML Platform for which Microsoft has released a fix on Tuesday, has likely been exploited by attackers in the wild for over a year, Check Point researcher Haifei Li has revealed.

"Check Point Research recently discovered that threat actors have been using novel tricks to lure Windows users for remote code execution. Specifically, the attackers used special Windows Internet Shortcut files, which, when clicked, would call the retired Internet Explorer to visit the attacker-controlled URL," he explained.

Url - would look as a benign file to most Windows users because it would point to a customized icon in the Microsoft Edge application file - in this case, an icon for PDF files.

This trick allows the attackers to continue hiding the file's true nature from the user who is intent on opening it by clicking through several pop-up warnings; the PDF file is actually a malicious HTA file, which executes and enables RCE. IE pop-up shows only the PDF extension.

Microsoft has been notified in May, and has now finally issued a patch, preventing URL files from triggering the MHTML: URI handler.

Morphisec researchers have warned that the patch for CVE-2024-38021 - a Microsoft Office vulnerability that can be exploited remotely and could lead to RCE - should also be implemented sooner rather than later.


News URL

https://www.helpnetsecurity.com/2024/07/10/cve-2024-38112-cve-2024-38021/

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2024-07-09 CVE-2024-38112 User Interface (UI) Misrepresentation of Critical Information vulnerability in Microsoft products
Windows MSHTML Platform Spoofing Vulnerability
network
high complexity
microsoft CWE-451
7.5
2024-07-09 CVE-2024-38021 Unspecified vulnerability in Microsoft products
Microsoft Outlook Remote Code Execution Vulnerability
network
low complexity
microsoft
8.8

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Microsoft 688 788 4527 4404 3626 13345