CVE-2024-30040
published 2024-05-14CVE-2024-30040: Windows MSHTML Platform Security Feature Bypass Vulnerability
PriorityP184high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2024-06-04
Exploited in the wild
EPSS
3.94%
89.2th percentile
Windows MSHTML Platform Security Feature Bypass Vulnerability
Affected
37 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1507 | < 10.0.10240.20651 | 10.0.10240.20651 |
| microsoft | windows_10_1607 | < 10.0.14393.6981 | 10.0.14393.6981 |
| microsoft | windows_10_1809 | < 10.0.17763.5820 | 10.0.17763.5820 |
| microsoft | windows_10_21h2 | < 10.0.19044.4412 | 10.0.19044.4412 |
| microsoft | windows_10_22h2 | < 10.0.19045.4412 | 10.0.19045.4412 |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.20651 | 10.0.10240.20651 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.6981 | 10.0.14393.6981 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.5820 | 10.0.17763.5820 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.5820 | 10.0.17763.5820 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.4412 | 10.0.19044.4412 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.4412 | 10.0.19045.4412 |
| microsoft | windows_11_21h2 | < 10.0.22000.2960 | 10.0.22000.2960 |
| microsoft | windows_11_22h2 | < 10.0.22621.3593 | 10.0.22621.3593 |
| microsoft | windows_11_23h2 | < 10.0.22631.3593 | 10.0.22631.3593 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.2960 | 10.0.22000.2960 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.3593 | 10.0.22621.3593 |
| microsoft | windows_11_version_22h3 | >= 10.0.22631.0 < 10.0.22631.3593 | 10.0.22631.3593 |
| microsoft | windows_11_version_23h2 | >= 10.0.22631.0 < 10.0.22631.3593 | 10.0.22631.3593 |
| microsoft | windows_server_2016 | < 10.0.14393.6981 | 10.0.14393.6981 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.6981 | 10.0.14393.6981 |
| microsoft | windows_server_2019 | < 10.0.17763.5820 | 10.0.17763.5820 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.5820 | 10.0.17763.5820 |
| microsoft | windows_server_2022 | < 10.0.20348.2458 | 10.0.20348.2458 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.2461 | 10.0.20348.2461 |
| microsoft | windows_server_2022_23h2 | < 10.0.25398.887 | 10.0.25398.887 |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2024-30040 exploits OLE/COM controls via a malicious document delivered over email or instant messenger; monitor for Office/365 processes spawning unexpected child processes after a user opens a document, as exploitation leads to arbitrary code execution in the user context. ↗
- →The vulnerability bypasses OLE mitigations in Microsoft 365 and Microsoft Office protecting against vulnerable COM/OLE controls; alert on suspicious COM/OLE object instantiation from Office application processes (e.g., WINWORD.EXE, EXCEL.EXE, OUTLOOK.EXE). ↗
- →Delivery vector is social engineering via email or instant messenger with a specially crafted file; monitor for suspicious file downloads or attachments opened from mail/IM clients that subsequently trigger MSHTML (mshtml.dll) loading within Office processes. ↗
- →Exploitation leads to downloading a malicious payload to the host; monitor for unexpected network connections or file writes initiated by Office/MSHTML processes following document open events. ↗
- →CVE-2024-30040 has confirmed in-the-wild exploitation; treat any unpatched Windows system running Microsoft 365 or Office as actively at risk and prioritize detection of MSHTML-based OLE bypass attempts. ↗
- ·The MSHTML platform is used throughout Microsoft 365 and Microsoft Office products, meaning the attack surface spans multiple Office applications, not just Internet Explorer/Edge legacy components. ↗
- ·User interaction is required but the user does NOT need to click or open the malicious file — merely manipulating (e.g., previewing) the specially crafted file is sufficient to trigger exploitation, widening the effective attack surface. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vulncheck8.8HIGH
cisa8.8HIGH
vendor_msrc8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mmh4-cvwv-5vmm: Windows MSHTML Platform Security Feature Bypass Vulnerability
ghsa_unreviewed·2024-05-14
CVE-2024-30040 [HIGH] CWE-20 GHSA-mmh4-cvwv-5vmm: Windows MSHTML Platform Security Feature Bypass Vulnerability
Windows MSHTML Platform Security Feature Bypass Vulnerability
VulnCheck
Microsoft Windows MSHTML Platform Security Feature Bypass Vulnerability
vulncheck·2024·CVSS 8.8
CVE-2024-30040 [HIGH] CWE-20 Microsoft Windows MSHTML Platform Security Feature Bypass Vulnerability
Microsoft Windows MSHTML Platform Security Feature Bypass Vulnerability
Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for a security feature bypass.
Affected: Microsoft Windows
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2024-May; https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30040; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.zerodayinitiative.com/blog/2024/5/14/the-may-2024-security-update-review; https://www.akamai.com/blog/security-research/akamai-perspective-patch-tuesday-may-2024#vulnerabilities; https://ti.qianxin.com/upload
Microsoft
Windows MSHTML Platform Security Feature Bypass Vulnerability
vendor_msrc·2024-05-14·CVSS 8.8
CVE-2024-30040 [HIGH] CWE-20 Windows MSHTML Platform Security Feature Bypass Vulnerability
Windows MSHTML Platform Security Feature Bypass Vulnerability
FAQ: What kind of security feature could be bypassed by successfully exploiting this vulnerability?
This vulnerability bypasses OLE mitigations in Microsoft 365 and Microsoft Office which protect users from vulnerable COM/OLE controls.
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
An attacker would have to convince the user to load a malicious file onto a vulnerable system, typically by way of an enticement in an Email or Instant Messenger message, and then convince the user to manipulate the specially crafted file, but not necessarily click or open the malicious file.
FAQ: How could an attacker exploit this vulnerability?
An unauthenticated attacker who su
CISA
Microsoft Windows MSHTML Platform Security Feature Bypass Vulnerability
cisa·2024-05-14·CVSS 8.8
CVE-2024-30040 [HIGH] CWE-20 Microsoft Windows MSHTML Platform Security Feature Bypass Vulnerability
Vulnerability: Microsoft Windows MSHTML Platform Security Feature Bypass Vulnerability
Affected: Microsoft Windows
Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for a security feature bypass.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30040; https://nvd.nist.gov/vuln/detail/CVE-2024-30040
Remediation Due Date: 2024-06-04
No detection rules found.
No public exploits indexed.
Tenable
Microsoft’s October 2024 Patch Tuesday Addresses 117 CVEs (CVE-2024-43572, CVE-2024-43573)
blogs_tenable·2024-10-08·CVSS 7.8
[HIGH] Microsoft’s October 2024 Patch Tuesday Addresses 117 CVEs (CVE-2024-43572, CVE-2024-43573)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Checkpoint
20th May – Threat Intelligence Report
blogs_checkpoint·2024-05-20
CVE-2024-30051 20th May – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 20th May – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 20th May, please download our Threat_Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Australian electronic prescriptions provider MediSecure suffered a significant ransomware attack, leading to widespread disruptions and data breaches. The impact of the attack has been profound, broadly affecting healthcare data broadly in the country.
WebTPA, an American healthcare management and administrative services provide
Qualys
Microsoft and Adobe Patch Tuesday, May 2024 Security Update Review
blogs_qualys·2024-05-14
Microsoft and Adobe Patch Tuesday, May 2024 Security Update Review
## Table of Contents
Microsoft Patch Tuesday for May 2024
Adobe Patches for May 2024
Zero-day Vulnerabilities Patched in May Patch Tuesday Edition
Critical Severity Vulnerability Patched in May Patch Tuesday Edition
Other Microsoft Vulnerability Highlights
Microsoft Release Summary
Discover and Prioritize Vulnerabilities inVulnerability Management, Detection & Response (VMDR)
Rapid Response withPatch Management (PM)
Qualys Monthly Webinar Series
Microsoft has released its May edition of Patch Tuesday. Let’s take a deep dive into the crucial insights from Microsoft’s Patch Tuesday updates for May 2024.
## Microsoft Patch Tuesday for May 2024
Microsoft Patch Tuesday’s May 2024 edition addressed 67 vulnerabilities, including one critical and 59 important severity vulnerabilities.
Krebs
Patch Tuesday, May 2024 Edition
blogs_krebs·2024-05-14·CVSS 8.8
CVE-2024-30051 [HIGH] Patch Tuesday, May 2024 Edition
Microsoft today released updates to fix more than 60 security holes in Windows computers and supported software, including two “zero-day” vulnerabilities in Windows that are already being exploited in active attacks. There are also important security patches available for macOS and Adobe users, and for the Chrome Web browser, which just patched its own zero-day flaw.
First, the zero-days. CVE-2024-30051 is an “elevation of privilege” bug in a core Windows library. Satnam Narang at Tenable said this flaw is being used as part of post-compromise activity to elevate privileges as a local attacker.
“CVE-2024-30051 is used to gain initial access into a target environment and requires the use of social engineering tactics via email, social media or instant messaging to convince a target to ope
Trendmicro
The May 2024 Security Update Review
blogs_trendmicro·2024-05-14·CVSS 7.8
[HIGH] The May 2024 Security Update Review
# The May 2024 Security Update Review
Get the May 2024 security update and review.
By: Dustin Childs
2024/05/14
Read time: ( words)
Save to Folio
Welcome to the second Tuesday of May. As expected, Adobe and Microsoft have released their standard bunch of security patches. Take a break from your regular activities and join us as we review the details of their latest advisories. If you’d rather watch the full video recap covering the entire release, you can check it out here:
Apple Patches for May 2024
Apple kicked off the May release cycle with a group of updates for their macOS and iOS platforms. Most notable is a fix for CVE-2024-23296 for iOS 16.7.8 and iPadOS 16.7.8. This vulnerability is a memory corruption issue in RTKit that could allow attackers to bypass kernel memory protec
Krebs
Patch Tuesday, May 2024 Edition
blogs_krebs·2024-05-14·CVSS 8.8
CVE-2024-30051 [HIGH] Patch Tuesday, May 2024 Edition
Microsoft today released updates to fix more than 60 security holes in Windows computers and supported software, including two “zero-day” vulnerabilities in Windows that are already being exploited in active attacks. There are also important security patches available for macOS and Adobe users, and for the Chrome Web browser, which just patched its own zero-day flaw.
First, the zero-days. CVE-2024-30051 is an “elevation of privilege” bug in a core Windows library. Satnam Narang at Tenable said this flaw is being used as part of post-compromise activity to elevate privileges as a local attacker.
“CVE-2024-30051 is used to gain initial access into a target environment and requires the use of social engineering tactics via email, social media or instant messaging to convince a target to ope
Qualys
Microsoft Patch Tuesday May 2024: Critical Fixes | Qualys
blogs_qualys·2024-05-14
Microsoft Patch Tuesday May 2024: Critical Fixes | Qualys
#### Table of Contents
- Microsoft Patch Tuesday for May 2024
- Adobe Patches for May 2024
- Zero-day Vulnerabilities Patched in May Patch Tuesday Edition
- Critical Severity Vulnerability Patched in May Patch Tuesday Edition
- Other Microsoft Vulnerability Highlights
- Microsoft Release Summary
- Discover and Prioritize Vulnerabilities inVulnerability Management, Detection & Response (VMDR)
- Rapid Response withPatch Management (PM)
- Qualys Monthly Webinar Series
Microsoft has released its May edition of Patch Tuesday. Let’s take a deep dive into the crucial insights from Microsoft’s Patch Tuesday updates for May 2024.
## Microsoft Patch Tuesday for May 2024
Microsoft Patch Tuesday’s May 2024 edition addressed 67 vulnerabilities, including one critical and 59 important severity vulne
Trendmicro
The May 2024 Security Update Review
blogs_trendmicro·2024-05-14·CVSS 7.8
[HIGH] The May 2024 Security Update Review
## The May 2024 Security Update Review
Get the May 2024 security update and review.
By: Dustin Childs 2024/05/14 Read time: ( words)
Save to Folio
Welcome to the second Tuesday of May. As expected, Adobe and Microsoft have released their standard bunch of security patches. Take a break from your regular activities and join us as we review the details of their latest advisories. If you’d rather watch the full video recap covering the entire release, you can check it out here:
Apple Patches for May 2024
Apple kicked off the May release cycle with a group of updates for their macOS and iOS platforms. Most notable is a fix for CVE-2024-23296 for iOS 16.7.8 and iPadOS 16.7.8 . This vulnerability is a memory corruption issue in RTKit that could allow attackers to bypass kernel memory prote
Tenable
Microsoft’s May 2024 Patch Tuesday Addresses 59 CVEs (CVE-2024-30051, CVE-2024-30040)
blogs_tenable·2024-05-14·CVSS 8.8
[HIGH] Microsoft’s May 2024 Patch Tuesday Addresses 59 CVEs (CVE-2024-30051, CVE-2024-30040)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bleepingcomputer
Microsoft May 2024 Patch Tuesday fixes 3 zero-days, 61 flaws
blogs_bleepingcomputer·2024-05-14·CVSS 8.8
[HIGH] Microsoft May 2024 Patch Tuesday fixes 3 zero-days, 61 flaws
## Microsoft May 2024 Patch Tuesday fixes 3 zero-days, 61 flaws
## Lawrence Abrams
17 Elevation of Privilege Vulnerabilities
2 Security Feature Bypass Vulnerabilities
27 Remote Code Execution Vulnerabilities
7 Information Disclosure Vulnerabilities
3 Denial of Service Vulnerabilities
4 Spoofing Vulnerabilities
The total count of 61 flaws does not include 2 Microsoft Edge flaws fixed on May 2nd and four fixed on May 10th.
To learn more about the non-security updates released today, you can review our dedicated articles on the new Windows 11 KB5037771 cumulative update and the Windows 10 KB5037768 update .
## Three zero-days fixed
This month's Patch Tuesday fixes two actively exploited and one publicly disclosed zero-day vulnerabilities.
Microsoft classifies a zero-day as a flaw
Crowdstrike
May 2024 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] May 2024 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Crowdstrike
July 2024 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] July 2024 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Crowdstrike
July 2024 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] July 2024 Patch Tuesday: Updates and Analysis
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
2024-05-14
Published
2024-05-14
Added to CISA KEV
Exploited in the wild