惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

云风的 BLOG
云风的 BLOG
有赞技术团队
有赞技术团队
Simon Willison's Weblog
Simon Willison's Weblog
人人都是产品经理
人人都是产品经理
L
LINUX DO - 最新话题
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
A
Arctic Wolf
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
小众软件
小众软件
Jina AI
Jina AI
The Cloudflare Blog
P
Palo Alto Networks Blog
AWS News Blog
AWS News Blog
阮一峰的网络日志
阮一峰的网络日志
C
Cybersecurity and Infrastructure Security Agency CISA
Know Your Adversary
Know Your Adversary
T
Threat Research - Cisco Blogs
L
Lohrmann on Cybersecurity
NISL@THU
NISL@THU
G
GRAHAM CLULEY
Project Zero
Project Zero
博客园_首页
博客园 - 三生石上(FineUI控件)
罗磊的独立博客
Spread Privacy
Spread Privacy
WordPress大学
WordPress大学
Hugging Face - Blog
Hugging Face - Blog
Latest news
Latest news
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
C
Cisco Blogs
C
Cyber Attacks, Cyber Crime and Cyber Security
T
Tor Project blog
S
Securelist
V
Vulnerabilities – Threatpost
T
The Exploit Database - CXSecurity.com
C
CERT Recently Published Vulnerability Notes
IT之家
IT之家
Google DeepMind News
Google DeepMind News
爱范儿
爱范儿
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
The Last Watchdog
The Last Watchdog
T
Tenable Blog
宝玉的分享
宝玉的分享
S
Secure Thoughts
P
Privacy & Cybersecurity Law Blog
量子位
大猫的无限游戏
大猫的无限游戏
J
Java Code Geeks
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
Security Archives - TechRepublic
Security Archives - TechRepublic

Vulnerabilities – ThreatDown by Malwarebytes

June 2025 Microsoft Patch Tuesday fixes two zero-days April 2025 Patch Tuesday includes one zero-day March 2025 Patch Tuesday, severity over quantity What is Cross-Site Scripting (XSS)? - ThreatDown by Malwarebytes Why ransomware gangs want you to keep using that GPON router - ThreatDown by Malwarebytes Hybrid cloud environments are not safe from ransomware Update now! Critical CVSS 10 vulnerability in Ivanti EPM - ThreatDown by Malwarebytes Update now! Four zero-days fixed in September Patch Tuesday - ThreatDown by Malwarebytes Ransomware gangs target SonicWall vulnerability
Windows MSHTML vulnerability actively exploited - ThreatDown by Malwarebytes
Pieter Arntz · 2024-09-18 · via Vulnerabilities – ThreatDown by Malwarebytes
Internet Explorer

CISA has added another MSHTML vulnerability rooted in Internet Explorer to its known exploited vulnerabilities catalog

The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2024-43461, a vulnerability in Windows MSHTML, to its known exploited vulnerabilities catalog. This requires Federal Civilian Executive Branch (FCEB) agencies to remediate the vulnerability by October 7, 2024.

A fix for the flaw was included in the September 2024 patch Tuesday, but at that time it wasn’t counted among the four zero-days that were patched as well, because Microsoft assumed that the vulnerability was only used in an attack chain with another MSHTML vulnerability, CVE-2024-38112, which was fixed in the July Patch Tuesday.

CVE-2024-43461 is a Windows MSHTML platform spoofing vulnerability, and another serious flaw that stems from the continued use of components of the—officially retired—Internet Explorer 11. Microsoft writes:

While Microsoft has announced retirement of the Internet Explorer 11 application on certain platforms and the Microsoft Edge Legacy application is deprecated, the underlying MSHTML, EdgeHTML, and scripting platforms are still supported.

Retaining fragments of Internet Explorer means that the outdated browser can still be invoked and leveraged for malicious purposes.

The MSHTML vulnerabilities were used by an APT group called Void Banshee to deploy malicious HTML Application (HTA) files camouflaged as PDF documents, which were able to hide their true file extension due to the way Internet Explorer prompts users after a file is downloaded.

An HTA file is an application that combines an HTML interface with programming logic in a scripting language supported by Internet Explorer, such as VBScript or JScript. As a fully trusted application, HTA files have more enhanced privileges than HTML files.

The HTA files were used to spread the Atlantida information stealer, which can steal passwords, authentication cookies, and cryptocurrency wallets from infected devices.

Successful exploitation requires an attacker to get a target to open a malicious file or visit a malicious website, but cybercriminals are well practiced at doing both.

Void Banshee is known for targeting organizations across North America, Europe, and Southeast Asia for financial gain and to steal data.

Malwarebytes and ThreatDown detect the Atlantida stealer as Spyware.Atlantida.

We don’t just report on vulnerabilities—we identify them, and prioritize action.

Cybersecurity risks should never spread beyond a headline. Keep vulnerabilities in check by using ThreatDown’s Vulnerability Assessment and Patch Management solutions.