cbcvebase.
CVE-2024-43461
published 2024-09-10

CVE-2024-43461: Windows MSHTML Platform Spoofing Vulnerability Windows MSHTML Platform Spoofing Vulnerability

high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2024-10-07
Exploited in the wild
EPSS
51.88%
98.8th percentile
Windows MSHTML Platform Spoofing Vulnerability Windows MSHTML Platform Spoofing Vulnerability

Affected

33 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10_version_1507>= 10.0.10240.0 < 10.0.10240.2076610.0.10240.20766
microsoftwindows_10_version_1607>= 10.0.14393.0 < 10.0.14393.733610.0.14393.7336
microsoftwindows_10_version_1809>= 10.0.17763.0 < 10.0.17763.629310.0.17763.6293
microsoftwindows_10_version_21h2>= 10.0.19043.0 < 10.0.19044.489410.0.19044.4894
microsoftwindows_10_version_22h2>= 10.0.19045.0 < 10.0.19045.489410.0.19045.4894
microsoftwindows_11_version_21h2>= 10.0.0 < 10.0.22000.319710.0.22000.3197
microsoftwindows_11_version_22h2>= 10.0.22621.0 < 10.0.22621.416910.0.22621.4169
microsoftwindows_11_version_22h3>= 10.0.22631.0 < 10.0.22631.416910.0.22631.4169
microsoftwindows_11_version_23h2>= 10.0.22631.0 < 10.0.22631.416910.0.22631.4169
microsoftwindows_11_version_24h2>= 10.0.26100.0 < 10.0.26100.174210.0.26100.1742
microsoftwindows_server_2008_r2_service_pack_1>= 6.1.7601.0 < 6.1.7601.273206.1.7601.27320
microsoftwindows_server_2008_service_pack_2>= 6.0.6003.0 < 6.0.6003.228706.0.6003.22870
microsoftwindows_server_2012>= 6.2.9200.0 < 6.2.9200.250736.2.9200.25073
microsoftwindows_server_2012_r2>= 6.3.9600.0 < 6.3.9600.221756.3.9600.22175
microsoftwindows_server_2016>= 10.0.14393.0 < 10.0.14393.733610.0.14393.7336
microsoftwindows_server_2019>= 10.0.17763.0 < 10.0.17763.629310.0.17763.6293
microsoftwindows_server_2022>= 10.0.20348.0 < 10.0.20348.270010.0.20348.2700
msrcwindows_10
msrcwindows_10_version_1607
msrcwindows_10_version_1809
msrcwindows_10_version_21h2
msrcwindows_10_version_22h2
msrcwindows_11_version_21h2
msrcwindows_11_version_22h2
msrcwindows_11_version_23h2

Detection & IOCsextracted from sources · hover to see the quote

filenameBooks_A0UJKO.pdf%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80%E2%A0%80.hta
other%E2%A0%80 (encoded braille whitespace, 26x repeated, used to hide .hta extension)
  • Hunt for HTA files whose names contain sequences of 26 repeated encoded braille whitespace characters (%E2%A0%80) between a spoofed extension (e.g. .pdf) and the real .hta extension — this is the exact obfuscation pattern used in CVE-2024-43461 exploitation.
  • Detect Windows Internet Shortcut files (.url extension) that force Internet Explorer to open attacker-controlled URLs — these were used as the initial delivery vector chained with CVE-2024-43461.
  • Monitor for HTA file downloads and subsequent execution via Internet Explorer's file-open prompt, particularly where the displayed filename ends in '...' — this indicates the .hta extension is being pushed out of the UI by whitespace padding.
  • Alert on the download and execution of HTA files that arrive disguised as PDF documents, as this was the payload delivery mechanism for the Atlantida info-stealer in CVE-2024-43461 exploitation.
  • CVE-2024-43461 was exploited as part of a two-CVE chain with CVE-2024-38112; detections should correlate .url file execution (CVE-2024-38112) followed by HTA download/execution (CVE-2024-43461) as a combined attack sequence.
  • ·Patching CVE-2024-43461 alone is insufficient — both the July 2024 (CVE-2024-38112) and September 2024 (CVE-2024-43461) security updates must be applied to fully break the attack chain.
  • ·The September 2024 patch does not strip the braille whitespace from filenames; it only ensures the real .hta extension is shown. Users may still be confused by the long whitespace padding into thinking the file is a PDF.
  • ·The MSHTML platform remains active and in scope even on systems where Internet Explorer 11 has been retired, because it is used by IE Mode in Edge and via the WebBrowser control in other applications.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
cvelistv58.8HIGH
vulncheck7.5HIGH
cisa7.5HIGH
vendor_msrc8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.