Security News > 2024 > September > Microsoft confirms second 0-day exploited by Void Banshee APT (CVE-2024-43461)

Microsoft confirms second 0-day exploited by Void Banshee APT (CVE-2024-43461)
2024-09-16 12:40

CVE-2024-43461, a spoofing vulnerability affecting Windows MSHTML – a software component used by various apps for rendering render web pages on Windows – “was exploited as a part of an attack chain relating to CVE-2024-38112, prior to July 2024,” Microsoft has revealed. The latter vulnerability was patched by the company in July 2024, and threat hunters with Trend Micro’s Zero Day Initiative explained that it had been used by the Void Banshee APT group to … More → The post Microsoft confirms second 0-day exploited by Void Banshee APT (CVE-2024-43461) appeared first on Help Net Security.


News URL

https://www.helpnetsecurity.com/2024/09/16/cve-2024-43461-exploited/

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2024-09-10 CVE-2024-43461 Unspecified vulnerability in Microsoft products
Windows MSHTML Platform Spoofing Vulnerability
network
low complexity
microsoft
8.8
2024-07-09 CVE-2024-38112 Unspecified vulnerability in Microsoft products
Windows MSHTML Platform Spoofing Vulnerability
network
high complexity
microsoft
7.5

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Microsoft 726 815 4740 4741 3650 13946