Microsoft Reclassifies Bug as Zero-Day Vulnerability CVE-2024-43461

17 Sep 2024

Microsoft Reclassifies Bug as Zero-Day Vulnerability

Microsoft has recently reclassified a previously addressed bug in its September Patch Tuesday update as a zero-day vulnerability. This flaw, designated as CVE-2024-43461, has been exploited by the advanced persistent threat group known as "Void Banshee" since before July. The vulnerability is categorized as a remotely exploitable platform-spoofing issue within the legacy MSHTML (Trident) browser engine, which Microsoft retains in Windows for backward compatibility.

Affects All Supported Windows Versions

This vulnerability impacts all supported versions of Windows, granting remote attackers the ability to execute arbitrary code on affected systems. However, for an exploit to be successful, an attacker must persuade a potential victim to visit a malicious webpage or click on an unsafe link.

Initially, Microsoft rated the severity of this flaw at 8.8 on the 10-point CVSS scale when it was disclosed on September 10. At that time, there was no indication that it was a zero-day vulnerability. On September 13, Microsoft revised its assessment, revealing that attackers had been actively exploiting the flaw as part of an attack chain related to CVE-2024-38112, another MSHTML platform spoofing vulnerability that was patched in July 2024. Microsoft stated, "We released a fix for CVE-2024-38112 in our July 2024 security updates which broke this attack chain."

To ensure full protection against exploits targeting CVE-2024-43461, Microsoft urges customers to apply patches from both the July and September 2024 updates. Following Microsoft’s update on September 13, the US Cybersecurity and Infrastructure Security Agency (CISA) added this flaw to its known exploited vulnerabilities database on September 16, setting an implementation deadline of October 7 for federal agencies to adopt the vendor’s mitigations.

Similarities to Previous Vulnerabilities

CVE-2024-43461 bears similarities to CVE-2024-38112, allowing attackers to manipulate user interfaces—specifically, the browser—to display misleading data. Check Point Research, credited by Microsoft for discovering CVE-2024-38112, described the flaw as enabling adversaries to send crafted URLs or Internet shortcut files that, when clicked, would trigger Internet Explorer to open a malicious URL, even if the browser is disabled. Additionally, Check Point noted that threat actors have employed a novel tactic to disguise malicious HTML application (HTA) files as harmless PDF documents during their exploits.

Trend Micro’s Zero Day Initiative (ZDI), which also claims credit for discovering CVE-2024-38112, reported that Void Banshee has exploited this vulnerability to deploy the Atlantida malware on Windows systems. In their observations, Trend Micro noted that the threat actor lured victims with malicious files masquerading as book PDFs, distributed through Discord servers, file-sharing websites, and other channels. Void Banshee is recognized as a financially motivated threat actor, targeting organizations across North America, Southeast Asia, and Europe.

A Two-Bug Microsoft Attack Chain

According to Microsoft’s updated advisory, attackers have been utilizing CVE-2024-43461 as part of a coordinated attack chain that also involves CVE-2024-38112. Researchers at Qualys previously indicated that exploits targeting CVE-2024-38112 would be equally effective against CVE-2024-43416, given their near-identical nature. Peter Girnus, a senior threat researcher at ZDI credited for CVE-2024-43461, explained that attackers leveraged CVE-2024-38112 to navigate to an HTML landing page through Internet Explorer using the MHTML protocol handler within a .URL file. "This landing page contains an HTML which downloads an HTA file where attackers can execute arbitrary code," Girnus elaborated.

How to use remote desktop connection on windows 11?

To use Remote Desktop Connection on Windows 11, follow these steps: 1. Open Settings and go to System > Remote Desktop. 2. Toggle on the 'Enable Remote Desktop' switch. 3. Note the PC name under 'PC name'. 4. On the computer that will be used to connect, open the Remote Desktop app. 5. Enter the PC name and click 'Connect'. 6. Enter the username and password of the remote computer. 7. Click 'OK' to connect.

How to crop a video on windows 10?

To crop a video on Windows 10, use the Photos app: 1. Open the Photos app and import the video. 2. Select the video and click 'Edit & Create'. 3. Choose 'Create a video with text'. 4. Drag the video to the timeline. 5. Click 'Trim' to cut the video length if needed. 6. Click 'Aspect ratio' to select the crop ratio. 7. Drag the video to adjust the crop area. 8. Click 'Finish video' to save the cropped video.
Close All Windows

Close All Windows download for free to PC or mobile

Latest update Close All Windows download for free for Windows PC or Android mobile

4
556 reviews
3217 downloads

News and reviews about Close All Windows

11 Sep 2025

Windows 11 Update 25H2 ISO Now Available for Early Access

Windows 11's update 25H2 is out on the Windows Insiders page as an ISO download. This update introduces visual tweaks, new widgets, and changes to File Explorer. Users must exercise caution due to previous updates causing issues with some SSDs.

Read more

11 Sep 2025

Evaluating Windows 11 Security Features Impact on User Safety

Exploring how certain Windows security features might inadvertently reduce safety, leading users to disable important protections.

Read more

11 Sep 2025

Windows 11 25H2 ISOs Now Available for Insiders

Microsoft has released Windows 11 version 25H2 ISOs to Insiders. The update is production-ready and introduces extended support cycles, enhancing user experience.

Read more

10 Sep 2025

HLT Feature Cautiously Withdrawn in Windows 95 Rollout

In 1995, Microsoft omitted the HLT instruction from Windows 95 due to concerns over system stability. This decision was made after recognizing potential risks in bricking machines from several manufacturers.

Read more

10 Sep 2025

Windows 11 Update Brings Key Security Fixes and Enhancements

Microsoft releases Windows 11 KB5065426 and KB5065431 to fix security vulnerabilities. Crucial updates install security patches and improve user interface. Upgrade Windows 11 for security and enhance device experience.

Read more

10 Sep 2025

Resale Market Faces Legal Scrutiny in UK Court Battle

The UK court is evaluating the legality of reselling Windows and Office licenses. This could impact the market for second-hand software, affecting software costs and availability across Europe and the UK.

Read more

10 Sep 2025

Windows 11 Update Introduces Exciting New Features

Microsoft unveils new features for Windows 11 version 23H2 and 24H2. From improved search capabilities to updated security and AI tools, this update offers advancements for both performance and user experience on Copilot+ PCs and beyond.

Read more

09 Sep 2025

Understanding Windows License During Upgrade to Windows 11

Explore how your existing Windows 10 license works as you upgrade to Windows 11 effortlessly with technical insights and compliance tips.

Read more

09 Sep 2025

Exploring Innovations in the Concept of Windows 12

With Windows 10 nearing its end, concept creators like Abdi imagine a potential Windows 12, highlighting features such as Collectzone, Files Panel, AI search, and enhanced widgets.

Read more

08 Sep 2025

Businesses Urged to Plan Post-Support Strategy for Windows 10

Microsoft ends Windows 10 support on October 14, 2025. Eligible users can enroll in the Extended Security Update program to receive critical patches until October 2026. It's essential to start planning for a transition to ensure uninterrupted tech security.

Read more