Check Point Uncovers Zero-Day Flaw in Windows, CVE-2024-38112

10 Jul 2024

Check Point Software Technologies has unveiled new information about CVE-2024-38112, a zero-day flaw in Windows that was recently patched as part of this month’s Patch Tuesday release. The vulnerability, which has been exploited in the wild, was discovered by Haifei Li, principal vulnerability researcher at Check Point.

According to Microsoft, the flaw is a spoofing vulnerability in the Windows MSHTML platform, with a CVSS score of 7.5. To exploit the vulnerability, an attacker would need to send a victim a malicious file that the victim would then have to execute.

In a thread on X (formerly Twitter), Li expressed some frustration with Microsoft’s handling of the patch release, stating that the company released the patch earlier than expected without notifying Check Point. However, Microsoft later reached out to Li to address the miscommunication and improve future coordination.

Technical Insights and Threat Actor Activities

Check Point Research published a blog post authored by Li, providing technical details about CVE-2024-38112. The post revealed that threat actors were using malicious Windows Internet Shortcut Files disguised as PDFs to gain remote code execution on victims’ machines.

Although Internet Explorer is no longer officially supported, the presence of its code in the Windows OS allows threat actors to exploit the flaw, even on systems without IE installed. The attacks observed by Check Point involved luring victims into clicking on .url files that would open the retired IE browser and visit an attacker-controlled URL.

While the identities of the threat actors remain unknown, Check Point’s research group manager, Eli Smadja, stated that at least two separate campaigns were likely responsible for the threat activity. One of the threat actors had a history of infostealer infections and targeted users in Turkey and Vietnam.

Overall, the discovery of CVE-2024-38112 highlights the ongoing challenges in cybersecurity and the importance of coordinated disclosure between researchers and vendors to protect users from potential exploits.

Alexander Culafi is a senior information security news writer and podcast host for TechTarget Editorial.

How to change screen timeout settings on windows 10?

To change screen timeout settings on Windows 10, follow these steps: 1. Open Settings by pressing Windows key + I. 2. Select 'System' and then choose 'Power & sleep' from the left menu. 3. Under the 'Screen' section, you can set the desired screen timeout duration for when your device is on battery power and when it's plugged in.

How to crop a video on windows 10?

To crop a video on Windows 10, you can use the Photos app: 1. Open the video in the Photos app. 2. Click 'Edit & Create' and select 'Trim' if you only want to cut the video down in length, or 'Create a video with text' and then use the 'Trim' and 'Resize' options. 3. Use the cropping handles to select the area you want to keep. 4. Click 'Save a copy' to save the cropped video.
Close All Windows

Close All Windows download for free to PC or mobile

Latest update Close All Windows download for free for Windows PC or Android mobile

4
556 reviews
3188 downloads

News and reviews about Close All Windows

30 Aug 2025

Microsoft and Phison Address SSD Concerns After Windows Update

Microsoft and Phison find no connection between SSD failures and the August 2025 Windows updates despite social media reports. Extensive tests show no widespread issue.

Read more

29 Aug 2025

Windows 11 Introduces New Features and Improvements for Insiders

The Windows 11 Insider Preview Build 26120.5770, released to the Beta Channel, includes new features like Copilot+, Braille Viewer, and various fixes. The update aims to enhance user experience through gradual feature rollouts and updates.

Read more

29 Aug 2025

Windows 11 Update Promises Enhanced Features for Developers

Microsoft prepares to release Windows 11 version 25H2, introducing features like mobile integration and improved search. The update will gradually reach users, focusing on subtle enhancements and a smooth transition.

Read more

29 Aug 2025

Windows 11 25H2 Nears Public Release with Minor Changes

Microsoft's Windows 11 25H2 update enters Release Preview, resetting the security update clock. Offering minor refinements and feature adjustments, it introduces policy changes for app management. Wider distribution is anticipated following the phased release strategy.

Read more

29 Aug 2025

Windows 11 Update 25H2 Opens for Release Preview Testing

Microsoft's Windows 11 version 25H2 is now in Release Preview testing. This update features enhancements from prior releases and expedites installation through a familiar servicing branch, benefiting enterprise and educational users.

Read more

28 Aug 2025

Microsoft's AI Vision for Windows Faces Skepticism

Microsoft's focus on AI-driven Windows leaves users desiring a system prioritizing keyboard, mouse, and reliability over agentic utilities.

Read more

27 Aug 2025

OOBE Enhances Windows Updates for Enterprises and Schools

Starting September 2025, OOBE will streamline updates for Windows 11 devices, offering increased security and compliance from the first use. Managed via Microsoft Intune, this change benefits Microsoft Entra joined devices, simplifying IT management and reducing post-deployment burdens.

Read more

27 Aug 2025

Windows 95 Continues to Power Egg Sorting Operations

A German farm near Düsseldorf still utilizes Windows 95 for efficient egg sorting, 30 years after its release.

Read more

27 Aug 2025

Windows 11 Enhances Android App Integration for Users

Windows 11 introduces a new Android integration with a Resume alert, allowing seamless app usage transition from phone to PC, enhancing productivity.

Read more

27 Aug 2025

Reflecting on Windows 95: A Pivotal Tech Moment 30 Years Later

Windows 95's launch in 1995 captivated audiences with its revolutionary GUI, altering the tech landscape and cementing Microsoft's leadership.

Read more