CVE-2024-43461
Windows MSHTML Platform Spoofing Vulnerability
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
- EPSS probability
- 54.49%
- CISA KEV
- Known exploited vulnerability
- CWE
- CWE-451
- Published
- 2024-09-10
- Last modified
- 2026-08-10
Affected products
- Microsoft Windows 11 Version 24H2
- Microsoft Windows 10 Version 1809
- Microsoft Windows Server 2019
- Microsoft Windows Server 2019 (Server Core installation)
- Microsoft Windows Server 2022
- Microsoft Windows 11 version 21H2
- Microsoft Windows 10 Version 21H2
- Microsoft Windows 11 version 22H2
Weakness type
Related vulnerabilities
- CVE-2026-79011 — UI misrepresentation in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engi
- CVE-2020-9236 — There is an improper interface design vulnerability in Huawei product. A module interface of the impated product does no
- CVE-2024-52277 — PDF Document Spoofing in DocuSeal
- CVE-2024-52276 — PDF Document Spoofing in DocuSign
- CVE-2024-52271 — PDF Document Spoofing in Documenso
- CVE-2024-52270 — PDF Document Spoofing in DropBox Sign(HelloSign)
- CVE-2024-52269 — AI Assistant PDF Document Spoofing in DocuSign
- CVE-2022-39258 — mailcow-dockerized critical information misrepresentation can lead to phishing attacks through Swagger UI