Microsoft confirms IE bug squashed in Patch Tuesday was exploited zero-day
ID: b67d8cf3-6bb6-5a26-bfc0-9ec1a4b5b18e
STIX ID: report--b67d8cf3-6bb6-5a26-bfc0-9ec1a4b5b18e
Feed Name: The Register (Security)
Threat Score
Microsoft confirmed that CVE-2024-43461 (an MSHTML file-type-spoofing bug, CVSS 8.8) was exploited as a zero-day in conjunction with CVE-2024-38112 to resurrect Internet Explorer and disguise .hta payloads, enabling the Void Banshee group to deliver the Atlantida info-stealer and exfiltrate credentials; disclosures and credit disputes between ZDI and Check Point are discussed and CISA added CVE-2024-43461 to its known exploited vulnerabilities catalog.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
