CISA Urges Federal Agencies to Address Windows MSHTML Vulnerability

18 Sep 2024

Federal Agencies Urged to Act Swiftly on MSHTML Vulnerability

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a directive to U.S. federal agencies, urging them to fortify their systems against a recently patched Windows MSHTML spoofing zero-day vulnerability. This flaw, identified as CVE-2024-43461, was brought to light during this month’s Patch Tuesday, initially leading Microsoft to classify it as non-exploited. However, a subsequent update revealed that the vulnerability had indeed been exploited prior to its resolution.

Microsoft disclosed that attackers had leveraged CVE-2024-43461 before July 2024, utilizing it as part of an exploit chain alongside another MSHTML spoofing bug, CVE-2024-38112. The company noted, “We released a fix for CVE-2024-38112 in our July 2024 security updates which broke this attack chain. Customers should apply both the July 2024 and September 2024 security updates to fully protect themselves.”

Peter Girnus, a threat researcher from the Trend Micro Zero Day Initiative (ZDI), reported that the Void Banshee hacking group exploited this vulnerability in zero-day attacks aimed at installing information-stealing malware. This particular vulnerability allows remote attackers to execute arbitrary code on unpatched Windows systems by deceiving users into visiting maliciously crafted webpages or opening harmful files.

The ZDI advisory elaborates on the flaw, stating, “The specific flaw exists within the way Internet Explorer prompts the user after a file is downloaded. A crafted file name can cause the true file extension to be hidden, misleading the user into believing that the file type is harmless. An attacker can leverage this vulnerability to execute code in the context of the current user.” In these attacks, the hackers utilized CVE-2024-43461 to deliver malicious HTA files disguised as PDF documents, cleverly concealing the .hta extension with 26 encoded braille whitespace characters (%E2%A0%80).

HTA file camouflaged as PDF document (Trend Micro)

Research conducted by Check Point and Trend Micro in July revealed that the Atlantida information-stealing malware deployed in these attacks is capable of pilfering passwords, authentication cookies, and cryptocurrency wallets from compromised devices. The Void Banshee group, first identified by Trend Micro, has gained notoriety for targeting organizations across North America, Europe, and Southeast Asia, primarily for financial gain and data theft.

Federal Agencies Given Three Weeks to Patch

In a proactive measure, CISA has included the MSHTML spoofing vulnerability in its Known Exploited Vulnerabilities catalog, designating it as actively exploited. Federal agencies are mandated to secure vulnerable systems within three weeks, with a deadline set for October 7, in accordance with Binding Operational Directive (BOD) 22-01. CISA emphasized, “These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.”

While CISA’s KEV catalog primarily serves to alert federal agencies about critical security flaws requiring immediate attention, private organizations globally are also encouraged to prioritize mitigation efforts for this vulnerability to thwart ongoing attacks. In addition to CVE-2024-43461, Microsoft has addressed three other actively exploited zero-days in the September 2024 Patch Tuesday, including CVE-2024-38217, which has been exploited in LNK stomping attacks since at least 2018 to bypass the Smart App Control and the Mark of the Web (MotW) security feature.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
7508546
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1735237
downloads
WinRAR

WinRAR

Streamline file management with fast compression, secure your documents, and save space.

5
735 reviews
746698
downloads
Minecraft

Minecraft

Shape environments, explore vast worlds, and survive against monsters with endless creativity.

5
750 reviews
495255
downloads

News and reviews for Desktop Windows

Visio 2021 Professional Now $9.97 Until February 8

Microsoft offers Visio 2021 Professional for $9.97, down from $249, with added templates, until February 8.

Read more

Code Vein Offers Stylish Combat, Discounted Editions

Code Vein captivates with anime-style combat and offers discounted editions. Fast-paced action meets fun builds in this cult classic.

Read more

Microsoft Phases Out RC4 in Kerberos for Windows Security

Microsoft to eliminate RC4 in Kerberos by July 2026, enhancing Windows security.

Read more

Highguard Faces Criticism but Shows Potential for Growth

Highguard, launched with controversy, holds potential despite poor reviews. Offering genre innovation, it aims to evolve against negative feedback.

Read more

PS2Recomp Boosts Native PS2 Games with Recompilation

PS2Recomp, a new tool, promises enhanced native PS2 game ports, sparking interest among developers for PC platforms.

Read more

NVIDIA Introduces RTX Remix Logic for Classic Game Mods

NVIDIA's RTX Remix Logic, launched on 2026-01-27, enables dynamic modding of classic PC games with a no-code node-based interface.

Read more

Windows 11 Update KB5074109 Affects Legacy Modems

The Windows 11 update KB5074109 disrupts modems by removing several legacy drivers, causing connectivity issues for select users.

Read more

Anytype Replaces Notion, Obsidian, and Todoist for Unified Workflow

Anytype consolidates Notion, Obsidian, and Todoist functions, reducing context-switching and improving workflow efficiency.

Read more

ReBlade: Cyberpunk Roguelike Announced by ChillyRoom

ReBlade from ChillyRoom and Spiral Up Games announced for PC: cyberpunk roguelike offers high-speed action in a dystopian setting.

Read more

Artorias Battles Elden Ring Bosses in New Video Showcase

Artorias from Dark Souls faces Elden Ring bosses, demonstrating impressive skills in Fights' YouTube video.

Read more