← back
CVE-2024-43573

Windows MSHTML Platform Spoofing Vulnerability

CVSS 6.5 MEDIUMEPSS 44.4%● KEVCWE-79
In short

A flaw in Windows MSHTML allows attackers to spoof web content or mislead users about the origin of web pages, potentially tricking them into trusting malicious sites.

Technical detail

CWE-79 vulnerability in MSHTML enables DOM-based spoofing attacks where an attacker can manipulate the rendering of web content to misrepresent its source or authenticity. Exploitation requires user interaction with a crafted webpage and affects the integrity of security indicators.

Summary generated and translated by AI from the official description.
Windows MSHTML Platform Spoofing Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:F/RL:O/RC:C

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →