CVE detail
CVE-2024-43573
Windows MSHTML Platform Spoofing Vulnerability
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 20.8 · diversity 14.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
7 source links · newest first
- 14th October – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 14th October, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Nonprofit healthcare organization Axis Health System has been hit by a ransomware attack by the Rhysida gang, leading to the theft of sensitive data, including mental health and substance abuse records. Rhysida […]
vendorresearch.checkpoint.comOct 14, 2024, 12:41 PM - Week in review: Microsoft fixes two exploited zero-days, SOC teams are losing trust in security toolsHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Microsoft patches two zero-days exploited in the wild (CVE-2024-43573, CVE-2024-43572) For October 2024 Patch Tuesday, Microsoft has released fixes for 117 security vulnerabilities, including two under active exploitation: CVE-2024-43573, a spoofing bug affecting the Windows MSHTML Platform, and CVE-2024-43572, a remote code execution flaw in the Microsoft Management Console (MMC). SOC teams are frustrated with their security tools Security operations … More →
newswww.helpnetsecurity.comOct 13, 2024, 8:00 AM - Microsoft October update patches two zero-day vulnerabilities it says are being actively exploitedCSO Online
The drama of Patch Tuesday often revolves around zero days, which in October’s haul of 117 vulnerabilities brings patch managers a total of five that have been publicly disclosed. Of those, Microsoft said that two are being actively exploited. The first is CVE-2024-43573, intriguingly a spoofing flaw in the Windows MSHTML component. If this doesn’t […]
newswww.csoonline.comOct 9, 2024, 4:52 PM - U.S. CISA adds Windows and Qualcomm bugs to its Known Exploited Vulnerabilities catalogSecurity Affairs
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Windows and Qualcomm bugs to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: Qualcomm this week addressed 20 vulnerabilities in its products, including a potential zero-day issue tracked as CVE-2024-43047 (CVSS score […]
newssecurityaffairs.comOct 9, 2024, 7:46 AM - Microsoft patches two zero-days exploited in the wild (CVE-2024-43573, CVE-2024-43572)Help Net Security
For October 2024 Patch Tuesday, Microsoft has released fixes for 117 security vulnerabilities, including two under active exploitation: CVE-2024-43573, a spoofing bug affecting the Windows MSHTML Platform, and CVE-2024-43572, a remote code execution flaw in the Microsoft Management Console (MMC). About CVE-2024-43573 and CVE-2024-43572 As far as it can be deduced from the accompanying advisory, CVE-2024-43573 is similar to CVE-2024-38112, a vulnerability in MSHTML, a browser engine for the now deprecated Internet Explorer, which has … More →
newswww.helpnetsecurity.comOct 8, 2024, 7:37 PM Patch Tuesday: Redmond warns that attackers are rigging Microsoft Saved Console (MSC) files to execute remote code on targeted Windows systems.
newswww.securityweek.comOct 8, 2024, 6:57 PM- October 2024 Patch Tuesday forecast: Recall can be recalledHelp Net Security
October 2024 Patch Tuesday is now live: Microsoft patches two zero-days exploited in the wild (CVE-2024-43573, CVE-2024-43572) October arrived, and Microsoft started the month by announcing the release of Windows 11 24H2. The preview versions of this release have been in the news due to many innovations and one controversial feature. Windows 11 24H2 and Microsoft Recall This OS was released in May for Microsoft’s new Copilot+ PCs, powered by a neural processing unit (NPU); … More →
newswww.helpnetsecurity.comOct 4, 2024, 4:40 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2024-43599CVSS 8.8 · High
Remote Desktop Client Remote Code Execution Vulnerability
- CVE-2024-43583CVSS 7.8 · High
Winlogon Elevation of Privilege Vulnerability
- CVE-2024-43572CVSS 7.8 · High
Microsoft Management Console Remote Code Execution Vulnerability
- CVE-2024-43570CVSS 6.4 · Medium
Windows Kernel Elevation of Privilege Vulnerability
- CVE-2024-43563CVSS 7.8 · High
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
- CVE-2024-43560CVSS 7.8 · High
Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability