⚠ Actively exploited
Added to CISA KEV on 2024-07-09. Federal agencies required to patch by 2024-07-30. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable..

CVE-2024-38112User Interface (UI) Misrepresentation of Critical Information in Microsoft Windows 10 Version 1507

Severity
7.5HIGHCNA
VulnCheck8.8
No vector
EPSS
93.0%
top 0.22%
CISA KEV
KEV
Added 2024-07-09
Due 2024-07-30
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedJul 9
KEV addedJul 9
KEV dueJul 30
Latest updateApr 1
CISA Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Description

Windows MSHTML Platform Spoofing Vulnerability Windows MSHTML Platform Spoofing Vulnerability

Affected Packages14 packages

CVEListV5microsoft/windows_server_201610.0.14393.010.0.14393.7159
CVEListV5microsoft/windows_server_201910.0.17763.010.0.17763.6054
CVEListV5microsoft/windows_server_202210.0.20348.010.0.20348.2582
CVEListV5microsoft/windows_server_2012_r26.3.9600.06.3.9600.22074
CVEListV5microsoft/windows_10_version_150710.0.10240.010.0.10240.20710

🔴Vulnerability Details

5
CVEList
Windows MSHTML Platform Spoofing Vulnerability2024-07-09
VulnCheck
Microsoft Windows MSHTML Platform Spoofing Vulnerability2024
VulnCheck
Microsoft Windows MSHTML Platform Spoofing Vulnerability2024
VulnCheck
Microsoft Windows SmartScreen Security Feature Bypass Vulnerability2023
VulnCheck
Microsoft MSHTML Remote Code Execution Vulnerability2021

📋Vendor Advisories

4
CISA
Microsoft Windows MSHTML Platform Spoofing Vulnerability2024-09-16
Microsoft
Windows MSHTML Platform Spoofing Vulnerability2024-09-10
CISA
Microsoft Windows MSHTML Platform Spoofing Vulnerability2024-07-09
Microsoft
Windows MSHTML Platform Spoofing Vulnerability2024-07-09

🕵️Threat Intelligence

27
Tenable
Microsoft Patch Tuesday 2024 Year in Review2024-12-10
Securelist
Exploits and vulnerabilities in Q3 20242024-12-06
Securelist
Analyzing the vulnerability landscape in Q3 20242024-12-06
Tenable
Microsoft’s October 2024 Patch Tuesday Addresses 117 CVEs (CVE-2024-43572, CVE-2024-43573)2024-10-08
Bleepingcomputer
CISA warns of Windows flaw used in infostealer malware attacks2024-09-16

📄Research Papers

1
arXiv
LLM-Assisted Proactive Threat Intelligence for Automated Reasoning2025-04-01
CVE-2024-38112 — Microsoft vulnerability | cvebase