← back
CVE-2024-38112

Windows MSHTML Platform Spoofing Vulnerability

CVSS 7.5 HIGHEPSS 84.3%● KEVCWE-451
In short

A flaw in Windows MSHTML allows attackers to spoof web content, making malicious websites appear as if they come from trusted sources. This tricks users into trusting fake or manipulated web pages.

Technical detail

This MSHTML vulnerability enables platform spoofing attacks where an attacker crafts malicious HTML content that misrepresents its origin or security context. The attack requires user interaction (CWE-451: User Interface (UI) Misrepresentation of Critical Information) and can lead to social engineering, credential theft, or malware distribution when users are deceived about the authenticity of web content.

Summary generated and translated by AI from the official description.
Windows MSHTML Platform Spoofing Vulnerability
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →