Attackers Have Been Leveraging Microsoft Zero-Day for 18 Months
ID: 73196710-0534-599a-80da-cf2794e5e029
STIX ID: report--73196710-0534-599a-80da-cf2794e5e029
Feed Name: Dark Reading
Check Point disclosed that CVE-2024-38112, a Microsoft MSHTML/Trident zero-day, has been exploited in the wild using specially crafted Internet Shortcut (.url) files that force use of Internet Explorer to retrieve and execute .hta payloads disguised as PDFs; attackers have used this technique to deploy the Atlantida information stealer in targeted campaigns affecting users in Vietnam and Turkey. Microsoft patched the flaw in the July update, CISA added it to its KEV catalog, and organizations are urged to apply mitigations or patch affected systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
