Advisory 73

Advisory 73: Microsoft Windows MSHTML Platform Spoofing Vulnerability

Release Date: 14th of September 2024

Impact : HIGH / CRITICAL

TLP Rating: Clear

CERT Vanuatu (CERTVU) and the Office of the Chief Information Officer (OGCIO) provide the following advisory.

What is it?

The Windows MSHTML Platform Spoofing Vulnerability refers to a security flaw within the MSHTML (Trident) engine, which is used by Internet Explorer and other applications that rely on web content rendering. The vulnerability allows attackers to craft a malicious web page or document that misrepresents or "spoofs" content, tricking the user into interacting with it under false pretenses.

References

  1. https://www.cisa.gov/news-events/alerts/2024/09/10/cisa-adds-four-known-exploited-vulnerabilities-catalog
  2. https://www.cve.org/CVERecord?id=CVE-2024-38217