logo

Attackers Have Been Leveraging Microsoft Zero-Day for 18 Months

ID: 73196710-0534-599a-80da-cf2794e5e029

STIX ID: report--73196710-0534-599a-80da-cf2794e5e029

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2024-07-10

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Check Point disclosed that CVE-2024-38112, a Microsoft MSHTML/Trident zero-day, has been exploited in the wild using specially crafted Internet Shortcut (.url) files that force use of Internet Explorer to retrieve and execute .hta payloads disguised as PDFs; attackers have used this technique to deploy the Atlantida information stealer in targeted campaigns affecting users in Vietnam and Turkey. Microsoft patched the flaw in the July update, CISA added it to its KEV catalog, and organizations are urged to apply mitigations or patch affected systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.