Windows MSHTML zero-day attacks unleash year-long wave of malware strikes

Windows MSHTML zero-day attacks: Microsoft fixes vulnerability
Spread the love
  • Microsoft fixed a Windows MSHTML zero-day vulnerability that has been exploited in attacks for over a year by unregistering the mhtml: URI from Internet Explorer
  • Haifei Li of Check Point Research discovered the high-severity CVE-2024-38112 vulnerability, exploited by distributing Windows Internet Shortcut Files to install password-stealing malware
  • Threat actors used Internet Explorer to download malicious HTA files disguised as PDFs, stealing browser credentials and sensitive data
  • Check Point Research released an emergency fix for the VPN zero-day vulnerability exploited in attacks
  • Microsoft’s July 2024 Patch Tuesday addressed 142 flaws, including four zero-day vulnerabilities, with a link to the Black Basta ransomware gang
Summarized Article:

https://www.bleepingcomputer.com/news/security/windows-mshtml-zero-day-used-in-malware-attacks-for-over-a-year/



Related Video
Published on: October 11, 2021 Description: In this episode, the Dark Web Deacon the details about the recent MSHTML zero day attack. Enjoy: What is a MSHTML Zero Day ...
What is a MSHTML Zero Day Attack? : Simply Explained
Play


Related Wikipedia Articles

Topics: No response

Response
Response may refer to: Call and response (music), musical structure Reaction (disambiguation) Request–response Output or response, the result of telecommunications input Response (liturgy), a line answering a versicle Response (music) or antiphon, a response to a psalm or other part of a religious service Response, a phase in emergency management...
Read more: Response

Author:

Leave a Reply

Your email address will not be published. Required fields are marked *