[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

254492

 
 

909

 
 

198541

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Windows MSHTML Platform Security Feature Bypass Vulnerability - CVE-2024-30040

ID: oval:org.secpod.oval:def:10000074Date: (C)2024-05-15   (M)2024-05-23
Class: VULNERABILITYFamily: windows




Windows MSHTML Platform Security Feature Bypass Vulnerability. This vulnerability bypasses OLE mitigations in Microsoft 365 and Microsoft Office which protect users from vulnerable COM/OLE controls. An attacker would have to convince the user to load a malicious file onto a vulnerable system, typically by way of an enticement in an Email or Instant Messenger message, and then convince the user to manipulate the specially crafted file, but not necessarily click or open the malicious file. An unauthenticated attacker who successfully exploited this vulnerability could gain code execution through convincing a user to open a malicious document at which point the attacker could execute arbitrary code in the context of the user.

Platform:
Microsoft Windows 10
Microsoft Windows 11
Microsoft Windows Server 2016
Microsoft Windows Server 2019
Microsoft Windows Server 2022
Microsoft Windows Server
Reference:
CVE-2024-30040
CVE    1
CVE-2024-30040
CPE    16
cpe:/o:microsoft:windows_10:1809::x64
cpe:/o:microsoft:windows_10:1809::x86
cpe:/o:microsoft:windows_server_2016:::x64
cpe:/o:microsoft:windows_10:1809
...

© SecPod Technologies