cbcvebase.
CVE-2024-30040
published 2024-05-14

CVE-2024-30040: Windows MSHTML Platform Security Feature Bypass Vulnerability

PriorityP184high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2024-06-04
Exploited in the wild
EPSS
3.94%
89.2th percentile
Windows MSHTML Platform Security Feature Bypass Vulnerability

Affected

37 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10_1507< 10.0.10240.2065110.0.10240.20651
microsoftwindows_10_1607< 10.0.14393.698110.0.14393.6981
microsoftwindows_10_1809< 10.0.17763.582010.0.17763.5820
microsoftwindows_10_21h2< 10.0.19044.441210.0.19044.4412
microsoftwindows_10_22h2< 10.0.19045.441210.0.19045.4412
microsoftwindows_10_version_1507>= 10.0.10240.0 < 10.0.10240.2065110.0.10240.20651
microsoftwindows_10_version_1607>= 10.0.14393.0 < 10.0.14393.698110.0.14393.6981
microsoftwindows_10_version_1809>= 10.0.0 < 10.0.17763.582010.0.17763.5820
microsoftwindows_10_version_1809>= 10.0.17763.0 < 10.0.17763.582010.0.17763.5820
microsoftwindows_10_version_21h2>= 10.0.19043.0 < 10.0.19044.441210.0.19044.4412
microsoftwindows_10_version_22h2>= 10.0.19045.0 < 10.0.19045.441210.0.19045.4412
microsoftwindows_11_21h2< 10.0.22000.296010.0.22000.2960
microsoftwindows_11_22h2< 10.0.22621.359310.0.22621.3593
microsoftwindows_11_23h2< 10.0.22631.359310.0.22631.3593
microsoftwindows_11_version_21h2>= 10.0.0 < 10.0.22000.296010.0.22000.2960
microsoftwindows_11_version_22h2>= 10.0.22621.0 < 10.0.22621.359310.0.22621.3593
microsoftwindows_11_version_22h3>= 10.0.22631.0 < 10.0.22631.359310.0.22631.3593
microsoftwindows_11_version_23h2>= 10.0.22631.0 < 10.0.22631.359310.0.22631.3593
microsoftwindows_server_2016< 10.0.14393.698110.0.14393.6981
microsoftwindows_server_2016>= 10.0.14393.0 < 10.0.14393.698110.0.14393.6981
microsoftwindows_server_2019< 10.0.17763.582010.0.17763.5820
microsoftwindows_server_2019>= 10.0.17763.0 < 10.0.17763.582010.0.17763.5820
microsoftwindows_server_2022< 10.0.20348.245810.0.20348.2458
microsoftwindows_server_2022>= 10.0.20348.0 < 10.0.20348.246110.0.20348.2461
microsoftwindows_server_2022_23h2< 10.0.25398.88710.0.25398.887

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2024-30040 exploits OLE/COM controls via a malicious document delivered over email or instant messenger; monitor for Office/365 processes spawning unexpected child processes after a user opens a document, as exploitation leads to arbitrary code execution in the user context.
  • The vulnerability bypasses OLE mitigations in Microsoft 365 and Microsoft Office protecting against vulnerable COM/OLE controls; alert on suspicious COM/OLE object instantiation from Office application processes (e.g., WINWORD.EXE, EXCEL.EXE, OUTLOOK.EXE).
  • Delivery vector is social engineering via email or instant messenger with a specially crafted file; monitor for suspicious file downloads or attachments opened from mail/IM clients that subsequently trigger MSHTML (mshtml.dll) loading within Office processes.
  • Exploitation leads to downloading a malicious payload to the host; monitor for unexpected network connections or file writes initiated by Office/MSHTML processes following document open events.
  • CVE-2024-30040 has confirmed in-the-wild exploitation; treat any unpatched Windows system running Microsoft 365 or Office as actively at risk and prioritize detection of MSHTML-based OLE bypass attempts.
  • ·The MSHTML platform is used throughout Microsoft 365 and Microsoft Office products, meaning the attack surface spans multiple Office applications, not just Internet Explorer/Edge legacy components.
  • ·User interaction is required but the user does NOT need to click or open the malicious file — merely manipulating (e.g., previewing) the specially crafted file is sufficient to trigger exploitation, widening the effective attack surface.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vulncheck8.8HIGH
cisa8.8HIGH
vendor_msrc8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.