HIGH

CVE-2024-38112

Microsoft Windows 10 1507 2024-07-09 CVSS v3.1
CVSS
7.5
KEV

Description

Windows MSHTML Platform Spoofing Vulnerability

Summary dbcve.org

Windows MSHTML Platform contains a spoofing vulnerability that could allow an attacker to present misleading or fraudulent content by exploiting the MSHTML rendering engine, potentially tricking users into trusting malicious web content or interfaces.

Mitigation

Apply the applicable Microsoft security updates for CVE-2024-38112 through Windows Update or manual patch deployment to affected Windows systems.

Patch Commit

Weakness (CWE)

CWE-451

EPSS Score

84.23%
Probability of exploitation in next 30 days
99.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE