Windows Vulnerability CVE-2024-43461 Reclassified as Previously Exploited

18 Sep 2024

A recently addressed vulnerability in Windows, known as the "MSHTML spoofing vulnerability" and tracked under CVE-2024-43461, has been reclassified as previously exploited following its use in attacks orchestrated by the Void Banshee APT hacking group. Initially disclosed during the September 2024 Patch Tuesday, Microsoft did not label the vulnerability as previously exploited at that time. However, a recent update to the CVE-2024-43461 advisory has confirmed its exploitation prior to the fix.

The flaw was uncovered by Peter Girnus, a Senior Threat Researcher at Trend Micro's Zero Day initiative. In comments to BleepingComputer, Girnus indicated that the CVE-2024-43461 vulnerability was leveraged in zero-day attacks by Void Banshee to deploy information-stealing malware. This APT group, first identified by Trend Micro, targets organizations across North America, Europe, and Southeast Asia, aiming to extract sensitive data for financial gain.

The CVE-2024-43461 Zero-Day

In July, both Check Point Research and Trend Micro reported on attacks that exploited Windows zero-days to compromise devices with the Atlantida info-stealer, a tool designed to pilfer passwords, authentication cookies, and cryptocurrency wallets from affected systems. These attacks utilized two zero-days: CVE-2024-38112, which was patched in July, and CVE-2024-43461, which received a fix this month, forming part of a broader attack chain.

The discovery of CVE-2024-38112 was credited to Check Point researcher Haifei Li, who explained that it was exploited to manipulate Windows into opening malicious websites in Internet Explorer instead of Microsoft Edge when specially crafted shortcut files were launched. "Specifically, the attackers used special Windows Internet Shortcut files (.url extension), which, when clicked, would invoke the retired Internet Explorer (IE) to navigate to an attacker-controlled URL," Li detailed in a July report.

These URLs facilitated the download of a malicious HTA file, prompting users to open it. Upon opening, a script would execute, leading to the installation of the Atlantida info-stealer. The HTA files cleverly employed the CVE-2024-43461 zero-day to obscure their true extension, presenting themselves as PDFs during the Windows prompt, thereby increasing the likelihood of user engagement.

Girnus elaborated on the exploitation, noting that the CVE-2024-43461 flaw enabled the creation of a CWE-451 condition through HTA file names that incorporated 26 encoded braille whitespace characters (%E2%A0%80), effectively concealing the .hta extension. The file name would appear as a PDF but included these braille characters followed by the .hta extension, as illustrated below:

Books_A0UJKO.pdf%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80.hta

When Windows attempted to open this file, the braille whitespace characters pushed the HTA extension out of the visible interface, leaving only a '...' string in the prompts. This clever manipulation made the HTA files appear as benign PDF files, thus increasing the chances of users inadvertently executing them.

Following the installation of the security update for CVE-2024-43461, Girnus noted that while the whitespace is no longer stripped, Windows now accurately displays the .hta extension in prompts.

Security update now shows HTA extensionSource: Peter Girnus

However, this fix is not...

How to set up remote desktop on windows 11 pro?

To set up Remote Desktop on Windows 11 Pro, follow these steps: 1) Go to Settings > System > Remote Desktop. 2) Set 'Enable Remote Desktop' to 'On' and confirm any prompts. 3) Note the PC name under 'PC name'. 4) On the remote device, open the Remote Desktop app and enter the PC name. 5) Click 'Connect' and enter your user credentials. Ensure both devices are connected to the internet and the remote connection is allowed through the firewall.

How to crop a video on windows 10?

To crop a video on Windows 10, you can use the built-in Photos app. Follow these steps: 1) Open the Photos app and import your video. 2) Click 'Edit & Create' and select 'Trim'. 3) Adjust the sliders to select the portion of the video you want to keep. 4) Click 'Save a copy' to save the cropped video. For more advanced cropping, consider using third-party software like Adobe Premiere Pro or free alternatives like Shotcut.
Close All Windows

Close All Windows download for free to PC or mobile

Latest update Close All Windows download for free for Windows PC or Android mobile

4
556 reviews
3188 downloads

News and reviews about Close All Windows

30 Aug 2025

Microsoft and Phison Address SSD Concerns After Windows Update

Microsoft and Phison find no connection between SSD failures and the August 2025 Windows updates despite social media reports. Extensive tests show no widespread issue.

Read more

29 Aug 2025

Windows 11 Introduces New Features and Improvements for Insiders

The Windows 11 Insider Preview Build 26120.5770, released to the Beta Channel, includes new features like Copilot+, Braille Viewer, and various fixes. The update aims to enhance user experience through gradual feature rollouts and updates.

Read more

29 Aug 2025

Windows 11 Update Promises Enhanced Features for Developers

Microsoft prepares to release Windows 11 version 25H2, introducing features like mobile integration and improved search. The update will gradually reach users, focusing on subtle enhancements and a smooth transition.

Read more

29 Aug 2025

Windows 11 25H2 Nears Public Release with Minor Changes

Microsoft's Windows 11 25H2 update enters Release Preview, resetting the security update clock. Offering minor refinements and feature adjustments, it introduces policy changes for app management. Wider distribution is anticipated following the phased release strategy.

Read more

29 Aug 2025

Windows 11 Update 25H2 Opens for Release Preview Testing

Microsoft's Windows 11 version 25H2 is now in Release Preview testing. This update features enhancements from prior releases and expedites installation through a familiar servicing branch, benefiting enterprise and educational users.

Read more

28 Aug 2025

Microsoft's AI Vision for Windows Faces Skepticism

Microsoft's focus on AI-driven Windows leaves users desiring a system prioritizing keyboard, mouse, and reliability over agentic utilities.

Read more

27 Aug 2025

OOBE Enhances Windows Updates for Enterprises and Schools

Starting September 2025, OOBE will streamline updates for Windows 11 devices, offering increased security and compliance from the first use. Managed via Microsoft Intune, this change benefits Microsoft Entra joined devices, simplifying IT management and reducing post-deployment burdens.

Read more

27 Aug 2025

Windows 95 Continues to Power Egg Sorting Operations

A German farm near Düsseldorf still utilizes Windows 95 for efficient egg sorting, 30 years after its release.

Read more

27 Aug 2025

Windows 11 Enhances Android App Integration for Users

Windows 11 introduces a new Android integration with a Resume alert, allowing seamless app usage transition from phone to PC, enhancing productivity.

Read more

27 Aug 2025

Reflecting on Windows 95: A Pivotal Tech Moment 30 Years Later

Windows 95's launch in 1995 captivated audiences with its revolutionary GUI, altering the tech landscape and cementing Microsoft's leadership.

Read more