PT-2024-5547 · Microsoft · Internet Explorer+3
Published
2024-08-13
·
Updated
2025-12-15
·
CVE-2024-38178
CVSS v2.0
7.6
High
| Vector | AV:N/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Edge versions prior to the fixed version
Microsoft Windows 10 version 1507 (prior to 10.0.10240.20751)
Description
The vulnerability is related to a memory corruption issue in the Windows Scripting Engine, which can be exploited by remote attackers to execute arbitrary code on a system. This issue has been linked to the North Korean APT group ScarCruft, who have been using it to infect devices with RokRAT malware. The attack vector involves exploiting the vulnerability through Internet Explorer Mode in Edge, and it can be triggered without any user interaction, such as when a user views a malicious advertisement. The estimated number of potentially affected devices worldwide is not specified, but the vulnerability has been used in real-world incidents, including the "Operation Code on Toast" campaign.
Recommendations
For Microsoft Edge versions prior to the fixed version: Update to the latest version of Microsoft Edge to patch the vulnerability.
For Microsoft Windows 10 version 1507 (prior to 10.0.10240.20751): Update to a newer version of Windows 10 or apply the patch for the vulnerability.
As a temporary workaround, consider disabling Internet Explorer Mode in Edge until a patch is available.
Restrict access to the Windows Scripting Engine to minimize the risk of exploitation.
Avoid using Internet Explorer or Edge in Internet Explorer compatibility mode until the issue is resolved.
Fix
RCE
Type Confusion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Internet Explorer
Edge
Windows
Windows 10