E24-iy8w1
CVSS:
7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
False Positive:
f
Variants:
2
Year:
2024
Description
This strike exploits a spoofing vulnerability in the Windows MSHTML platform. The vulnerability arises from improper validation of link addresses in Internet Shortcut Files (".url" extension). When a specially crafted ".url" file is opened, the URL is incorrectly handled if it starts with a protocol prefix like "mhtml:". This improper handling can result in requests being made to an attacker-controlled location. The attacker can also control the icon and appearance of the ".url" file, making it misleading to users.
A remote attacker can exploit this vulnerability by tricking a target user into opening a crafted ".url" file, which could lead to spoofing attacks or NTLM relay attacks, potentially exposing authentication details.
CVE
References
https://research.checkpoint.com/2024/resurrecting-internet-explorer-threat-actors-using-zero-day-tricks-in-internet-shortcut-file-to-lure-victims-cve-2024-38112/