{"cveID":"CVE-2024-38112","vendorProject":"Microsoft","product":"Windows","vulnerabilityName":"Microsoft Windows MSHTML Platform Spoofing Vulnerability","dateAdded":"2024-07-09","shortDescription":"Microsoft Windows MSHTML Platform contains a spoofing vulnerability that has a high impact to confidentiality, integrity, and availability.","requiredAction":"Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.","dueDate":"2024-07-30","knownRansomwareCampaignUse":"Unknown","notes":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38112; https://nvd.nist.gov/vuln/detail/CVE-2024-38112","cwes":["CWE-451"],"year":2024,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2024-38112","technique":"T1189","technique_name_at_mapping":"Drive-by Compromise","mapping_type":"exploitation_technique","capability_group":"spoofing_vuln","comments":"This vulnerability is exploited through a victim visiting a malicious Web page or to clicking on an unsafe link. After visiting the website or clicking on the link, an adversary would gain the ability to execute arbitrary code on the victim system.","references":["https://www.darkreading.com/application-security/void-banshee-exploits-second-microsoft-zero-day"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2024-38112","technique":"T1204.001","technique_name_at_mapping":"Malicious Link","mapping_type":"exploitation_technique","capability_group":"spoofing_vuln","comments":"This vulnerability is exploited through a victim visiting a malicious Web page or to clicking on an unsafe link. After visiting the website or clicking on the link, an adversary would gain the ability to execute arbitrary code on the victim system.","references":["https://www.darkreading.com/application-security/void-banshee-exploits-second-microsoft-zero-day"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1189","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Drive-by Compromise","name_at_mapping":"Drive-by Compromise","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":3,"has_detection_strategy":true},{"id":"T1204.001","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Malicious Link","name_at_mapping":"Malicious Link","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":4,"has_detection_strategy":true}],"mapping_types":["exploitation_technique"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"full","sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-23 05:47 UTC","_attack_version":"19.2"}