Microsoft Discloses MSHTML Vulnerability, Urges Immediate Security Updates

17 Sep 2024

Microsoft's Security Vulnerability Exposes Long-Standing Risks

A recent development from Microsoft has cast a shadow over last week’s Patch Tuesday, revealing a security vulnerability that harkens back to the days of Internet Explorer. This long-dormant code, hidden within the operating systems of hundreds of millions of PCs, has become a target for threat actors, exposing a significant security gap that demands immediate attention.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has swiftly included CVE-2024-43461 in its Known Exploited Vulnerabilities (KEV) catalog. This vulnerability is characterized as a user interface misrepresentation within the Microsoft Windows MSHTML Platform, enabling attackers to spoof web pages effectively. CISA has indicated that this vulnerability has been exploited in tandem with CVE-2024-38112, a threat previously reported in July.

Check Point, a cybersecurity firm, raised alarms back in July, noting that attackers have been utilizing specialized Windows Internet Shortcut files to launch URLs through Internet Explorer instead of more modern browsers like Chrome or Edge. This tactic grants attackers a distinct advantage, allowing them to exploit vulnerabilities even on systems running the latest versions of Windows 10 and 11.

CISA has set a deadline of October 7 for all Windows PCs to be updated, a directive primarily aimed at federal employees but often followed by various public and private organizations. This initiative underscores CISA’s mission to assist organizations in managing vulnerabilities and staying ahead of emerging threats.

For those who updated their systems since July, one of the two vulnerabilities in this exploit chain has already been addressed. The latest updates will patch the second vulnerability. Trend Micro’s Zero Day Initiative (ZDI) has highlighted that this vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows, typically initiated through a malicious webpage that users are tricked into visiting.

Microsoft has clarified that the MSHTML platform is utilized by Internet Explorer mode in Microsoft Edge and other applications via the WebBrowser control. To ensure comprehensive protection, the company recommends that customers installing Security Only updates also apply the Internet Explorer Cumulative updates addressing this vulnerability.

Furthermore, Microsoft has noted that CVE-2024-43461 was exploited as part of an attack chain linked to CVE-2024-38112 prior to July 2024. A fix for CVE-2024-38112 was released in July, effectively severing this attack chain. However, users who have not updated since then remain vulnerable to both threats, having overlooked the previous CISA deadline of July 30.

In addition to addressing the recent MSHTML vulnerabilities, September’s Patch Tuesday also tackled four other zero-day vulnerabilities, leading to an October 1 update deadline set by CISA. This situation mirrors recent developments with Android and Chrome, highlighting the necessity for organizations to navigate multiple CISA mandates with varying deadlines.

As previously reported, the attribution for the exploitation of MSHTML vulnerabilities has been linked to the advanced persistent threat group known as Void Banshee. This group employs tactics such as luring victims with zip archives containing malicious files disguised as book PDFs, disseminated through cloud-sharing platforms, Discord servers, and online libraries. Trend Micro warns that the capability of APT groups like Void Banshee to exploit outdated services like Internet Explorer poses a serious threat to organizations globally.

CISA continues to emphasize the importance of applying mitigations as per vendor instructions or discontinuing use of affected products if no mitigations are available. This directive underscores the urgency for users to either update their systems promptly or risk exposure to these significant threats.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6740956
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1429258
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
576566
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
463446
downloads

News and reviews for Desktop Windows

Highlights from PC Gaming Show: Most Wanted 2025 Countdown

PC Gaming Show: Most Wanted 2025 on December 4 reveals top PC games with new trailers and announcements. Anticipated by gamers and industry experts.

Read more

Microsoft Alters LNK File Behavior to Tackle Vulnerability

Microsoft changes LNK file handling in response to exploited vulnerability CVE-2025-9491, affecting multiple cybercrime groups.

Read more

Norsca Rework Highlights Tides of Torment Expansion

Tides of Torment expansion releases 2023-12-04, with Norsca rework featuring new units and mechanics for Sayl the Faithless.

Read more

Microsoft Ad Promotes Copilot, Sparks Mixed Reactions

Microsoft released a Windows 11 ad featuring Copilot, aiming to showcase advanced voice integration. The ad has sparked mixed reactions, potentially inflating expectations.

Read more

Windows Accessibility Upgrades Enhance User Experience

Windows enhances accessibility with new voice and dictation features, benefiting diverse user needs in 2025.

Read more

Helldivers 2 Trims PC Install Size by 85%

Helldivers 2's PC install size reduced to 23 GB from 154 GB, thanks to deduplication efforts by Arrowhead Game Studios and Nixxes Software.

Read more

PCGamingShow to Reveal Top 25 PC Games by 2025

PC Gamer hosts PCGamingShow: Most Wanted on 2025-12-04, unveiling top PC games. Streaming globally, includes exciting game trailers and announcements.

Read more

Windows Concept Imagines 'Liquid Glass' Redesign

YouTube creator unveils Liquid Glass design, reshaping Windows with modern features that fans want Microsoft to consider.

Read more

Fanatical's $10 Bundle Offers PC Board Games Until December

Fanatical's new bundle offers discounted digital board games for $10. Available globally until 2023-12-22. Limited Steam codes, move fast.

Read more

Remove Malicious Rust Crate Targeting EVM Systems

A Rust crate on crates.io posed security risks to EVM systems. Removed after 7,000+ downloads, it affected Windows, macOS, and Linux.

Read more