Vulnerability record · CVE-2024-43461 · published 10 September 2024
CVE-2024-43461: Windows MSHTML Platform spoofing flaw enables code execution
Microsoft · Windows 10 1507
CVE-2024-43461 is a spoofing vulnerability in the Windows MSHTML platform, the legacy rendering engine still reachable through Windows components. The CVSS vector rates it high severity with full confidentiality, integrity and availability impact, and CISA added it to the Known Exploited Vulnerabilities catalog, so it is being used in the wild.
Description
Windows MSHTML Platform Spoofing Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is in CISA KEV with active exploitation and a high CVSS score, but requires user interaction and the record gives no confirmed pre-auth remote code execution detail.
What it is
CVE-2024-43461 is a spoofing vulnerability in the Windows MSHTML platform, the legacy rendering engine still reachable through Windows components. The CVSS vector rates it high severity with full confidentiality, integrity and availability impact, and CISA added it to the Known Exploited Vulnerabilities catalog, so it is being used in the wild.
Impact
An attacker who convinces a user to open crafted content can spoof what the user sees and, per the CVSS impact ratings, gain high confidentiality, integrity and availability impact on the target. The record does not specify the exact end effect beyond spoofing and those impact metrics.
Attack surface
Reachable over the network (AV:N) with no privileges required (PR:N), but it needs user interaction (UI:R), meaning a victim must open or view attacker-controlled content that triggers the MSHTML platform. No authentication is needed on the attacker side.
Exploitation
CISA added it to KEV on 2024-09-16 with a remediation due date of 2024-10-07, and EPSS gives a 30-day probability of about 0.545 (98.9th percentile), indicating active exploitation. No ransomware campaign use is recorded.
What to do
- Apply the Microsoft security update for CVE-2024-43461 across all listed Windows client and server versions.
- Prioritize internet-facing and user-workstation systems, and meet the CISA KEV remediation deadline of 2024-10-07.
- Reduce exposure to the legacy MSHTML engine where business needs allow, and restrict untrusted web and document content.
- Verify patching through your vulnerability management tooling and confirm the MSHTML component is updated, not just the OS build.
Detection
- Hunt for processes loading mshtml.dll or related MSHTML components spawned from browsers, Office or email clients.
- Monitor for suspicious child processes and network connections originating from MSHTML hosting processes.
- Alert on exploitation indicators tied to CVE-2024-43461 in EDR and network telemetry, and review KEV-related advisories for updated signatures.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-43461 to the Known Exploited Vulnerabilities catalog on 16 September 2024 as "Microsoft Windows MSHTML Platform Spoofing Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 7 October 2024.
Affected products
15 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43461 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-43461 | US Government Resource |
Track CVE-2024-43461 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-43461), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.