HIGH
CVE-2024-38112
CVSS
7.5
KEV
Description
Windows MSHTML Platform Spoofing Vulnerability
Summary dbcve.org
Windows MSHTML Platform contains a spoofing vulnerability that could allow an attacker to present misleading or fraudulent content by exploiting the MSHTML rendering engine, potentially tricking users into trusting malicious web content or interfaces.
Mitigation
Apply the applicable Microsoft security updates for CVE-2024-38112 through Windows Update or manual patch deployment to affected Windows systems.
Weakness (CWE)
CWE-451
EPSS Score
84.23%
Probability of exploitation in next 30 days
99.7th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.