Windows MSHTML Platform Spoofing Vulnerability
Published: 2024-07-09
Microsoft addresses 138 CVEs in its July 2024 Patch Tuesday release, with five critical vulnerabilities and three zero-day vulnerabilities, two of which were exploited in the wild.
https://securelist.com/exploits-and-vulnerabilities-q3-2024/114839/
https://www.theregister.com/2024/09/17/microsoft_zero_day_spoofing_flaw/
https://thehackernews.com/2024/07/void-banshee-apt-exploits-microsoft.html
https://www.trendmicro.com/en_us/research/24/g/CVE-2024-38112-void-banshee.html
https://www.theregister.com/2024/07/15/zdi_microsoft_vulnerability/
Published: 2024-07-09
Updated: 2025-01-27
Named Vulnerability: Void BansheeNamed Vulnerability: Microsoft Windows MSHTML Platform Spoofing VulnerabilityNamed Vulnerability: Microsoft Windows MSHTMLKnown Exploited Vulnerability (KEV)
Base Score: 7.6
Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C
Severity: High
Base Score: 7.5
Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity: High
EPSS: 0.91779