logo

Microsoft confirms IE bug squashed in Patch Tuesday was exploited zero-day

ID: b67d8cf3-6bb6-5a26-bfc0-9ec1a4b5b18e

STIX ID: report--b67d8cf3-6bb6-5a26-bfc0-9ec1a4b5b18e

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2024-09-17

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Microsoft confirmed that CVE-2024-43461 (an MSHTML file-type-spoofing bug, CVSS 8.8) was exploited as a zero-day in conjunction with CVE-2024-38112 to resurrect Internet Explorer and disguise .hta payloads, enabling the Void Banshee group to deliver the Atlantida info-stealer and exfiltrate credentials; disclosures and credit disputes between ZDI and Check Point are discussed and CISA added CVE-2024-43461 to its known exploited vulnerabilities catalog.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.