Threat Advisory

Microsoft Releases Patch for Exploited MSHTML Zero-Day Vulnerability in Windows

Threat: Vulnerability
Targeted Region: Southeast Asia, Europe & North America
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A newly discovered Windows MSHTML platform spoofing vulnerability, CVE-2024-43461, has been exploited by the Void Banshee APT group, affecting all supported Windows versions. Attackers lure victims by distributing malicious files disguised as PDF documents within zip archives, often found on cloud-sharing sites, Discord servers, and online libraries. The exploitation involves users clicking on Windows Internet Shortcut (.url) files that redirect to malicious websites, where an HTML Application (HTA) file is downloaded, executing a script to install the Atlantida info-stealer malware. The attack cleverly uses braille whitespace characters to obscure the true file extension, enhancing its potential for user deception. Additionally, the Void Banshee group's attack campaign also utilizes CVE-2024-38112, a resolved vulnerability that further aids their exploitative methods. Users are urged to exercise extreme caution when opening .url files from unknown sources, as the attack relies heavily on user engagement.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A newly discovered Windows MSHTML platform spoofing vulnerability, CVE-2024-43461, has been exploited by the Void Banshee APT group, affecting all supported Windows versions. Attackers lure victims by distributing malicious files disguised as PDF documents within zip archives, often found on cloud-sharing sites, Discord servers, and online libraries. The exploitation involves users clicking on Windows Internet Shortcut (.url) files that redirect to malicious websites, where an HTML Application (HTA) file is downloaded, executing a script to install the Atlantida info-stealer malware. The attack cleverly uses braille whitespace characters to obscure the true file extension, enhancing its potential for user deception. Additionally, the Void Banshee group's attack campaign also utilizes CVE-2024-38112, a resolved vulnerability that further aids their exploitative methods. Users are urged to exercise extreme caution when opening .url files from unknown sources, as the attack relies heavily on user engagement.[emaillocker id="1283"]

RECOMMENDATION:

We strongly recommend applying an update for Windows MSHTML Platform Spoofing Vulnerability

•  Download here: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43461

REFERENCES:

The following reports contain further technical details:
https://cybersecuritynews.com/windows-mshtml-zero-day-exploit/

[/emaillocker]
crossmenu