logo

Windows MSHTML zero-day used in malware attacks for over a year

ID: 863d68d6-8403-586e-8bef-52970e4de0ac

STIX ID: report--863d68d6-8403-586e-8bef-52970e4de0ac

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-07-10

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Microsoft patched CVE-2024-38112, a high-severity MHTML spoofing zero-day that threat actors abused to invoke Internet Explorer via crafted .url files and the mhtml: URI; IE would download HTA files disguised as PDFs (using Unicode padding) which, when executed, installed the Atlantida stealer to harvest credentials, cookies, wallets, and other sensitive data. Check Point found samples dating back to January 2023, and Microsoft mitigated the issue in July 2024 by unregistering the mhtml: handler so Edge handles the content.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.