HIGH

CVE-2024-43573

Microsoft Windows 10 1507 2024-10-08 CVSS v3.1
CVSS
8.1
KEV

Description

Windows MSHTML Platform Spoofing Vulnerability

Summary dbcve.org

This is a spoofing vulnerability in the Windows MSHTML platform (the legacy Trident rendering engine used by Internet Explorer and embedded in other Windows applications). An attacker could potentially exploit this to misrepresent or impersonate content rendered by the MSHTML engine, likely by manipulating how the platform identifies or displays content. The high CVSS score indicates significant impact when combined with attack complexity.

Mitigation

Apply the Microsoft security update for CVE-2024-43573 to all affected Windows systems as soon as possible; consider disabling MSHTML in environments where Internet Explorer mode is not required.

Patch Commit

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

46.11%
Probability of exploitation in next 30 days
98.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE