PT-2024-6158 · Microsoft · Windows

Gothburz

+1

·

Published

2024-09-10

·

Updated

2025-12-30

·

CVE-2024-43461

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Windows versions prior to the fixed version
Description The issue is related to a Windows MSHTML platform spoofing vulnerability, which allows attackers to execute arbitrary code remotely. This vulnerability has been exploited by the Void Banshee APT group in zero-day attacks, delivering malicious HTML Application (HTA) files camouflaged as PDF documents to spread the Atlantida information stealer. The attackers used a technique involving 26 Braille space characters to hide the extension of the malicious HTA file. The vulnerability affects all supported Windows versions and has been addressed by Microsoft in their July and September 2024 updates.
Recommendations To resolve the issue, apply the July and September 2024 updates to fully protect against exploits targeting this vulnerability. Ensure your operating system is up-to-date to protect against threats related to this vulnerability.

Fix

UI Misrepresentation of Critical Information

Weakness Enumeration

Related Identifiers

BDU:2024-07077
CVE-2024-43461
ZDI-24-1207

Affected Products

Windows