High // HIGH CVE-2024-38112

Windows MSHTML Spoofing Vulnerability Exploited via Shortcut Files (.url) Targeting Activists

Published by Tech Mentor Threat Intelligence Team
// Technical Threat Dossier
Vulnerability ID (CVE ID): CVE-2024-38112
Estimated Severity Level: High // HIGH
Affected Systems & Software: Microsoft Windows & MSHTML Engine
Patch / Update Availability: 2024-07-09

Vulnerability Nature & Exploitation:

Threat actors utilized specially crafted internet shortcut files (.url) distributed inside zip archives. When launched, the shortcut forced the invocation of the deprecated Internet Explorer (MSHTML) engine in the background—even if the default browser was Chrome or Edge—bypassing security controls and dropping malicious payloads.

Remediation Steps:

  • Windows Cumulative Update: Install the Microsoft July 2024 security updates immediately.
  • File Hygiene: Never open untrusted .url or shortcut files received via email or messaging platforms.
⚡ Do you suspect you are being targeted by this exploit?

Helpline team is on standby to provide diagnosis and digital triage free of charge with complete confidentiality.

Open Emergency Helpline Ticket →