← back
CVE-2024-30040

Windows MSHTML Platform Security Feature Bypass Vulnerability

CVSS 8.8 HIGHEPSS 3.9%● KEVCWE-20
In short

A security feature in Windows MSHTML (the rendering engine used by Internet Explorer and some Windows components) can be bypassed, allowing attackers to bypass protections that would normally prevent malicious actions. This matters because it could allow attackers to run arbitrary code or access sensitive information on affected systems.

Technical detail

This vulnerability in the MSHTML rendering engine permits circumvention of platform-level security mechanisms through improper input validation (CWE-20). An attacker can craft malicious content that exploits this bypass to execute code or escalate privileges; the attack vector is typically web-based (via compromised or malicious HTML content). The high CVSS score (8.8) indicates significant impact on system integrity and confidentiality.

Summary generated and translated by AI from the official description.
Windows MSHTML Platform Security Feature Bypass Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →