“Void Banshee” Unleashes Second Microsoft Zero-Day Vulnerability

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Microsoft Zero-Day Vulnerability Exploited by Void Banshee Threat Group

Microsoft has identified a critical zero-day vulnerability, CVE-2024-43461, that has been exploited by the “Void Banshee” advanced persistent threat group. This vulnerability resides in the legacy MSHTML (Trident) browser engine included in Windows for backward compatibility. The bug allows remote attackers to execute arbitrary code on all supported Windows versions, making it a serious threat.

Initially rated 8.8 on the CVSS scale, Microsoft confirmed active exploitation of the vulnerability as part of an attack chain related to CVE-2024-38112. To mitigate this risk, Microsoft urges users to apply patches from both the July and September updates. The US CISA has added this flaw to its exploited vulnerabilities database, setting a deadline for mitigation by October 7.

The attack chain involves exploiting two similar vulnerabilities, with Void Banshee utilizing CVE-2024-38112 to lead victims to a malicious page through Internet Explorer. By using CVE-2024-43461 to spoof a PDF file as a harmless HTA file, attackers trick unsuspecting users into downloading malware onto their systems.

Experts warn that the reliance on outdated components like MSHTML increases the attack surface for organizations. A study revealed that a significant number of Windows systems lack essential security controls, leaving them vulnerable to exploitation. It is crucial for enterprises to address these environmental vulnerabilities and stay vigilant against emerging threats like CVE-2024-43461.

As cyber threats continue to evolve, proactive measures such as timely patching and robust security controls are essential to safeguarding sensitive data and preventing malicious actors from exploiting critical vulnerabilities like CVE-2024-43461.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

European Parliament Calls for Delay in Serbia’s EU Accession Over Spyware Concerns

A group of European Parliament representatives is advocating for a delay in Serbia's entry into the European Union due to concerns over the government's...

Estate Planning in the UAE Embraces Digital Transformation, Says Blanket Founder

UAE Estate Planning Enters Digital Transformation Era The UAE is witnessing a significant shift in estate planning as the traditionally complex process begins to embrace...

Edge AI Shifts Security Responsibilities to Customers in New Trust Model

Edge AI shifts the responsibility of security from centralized cloud providers to customers, fundamentally altering the trust model for AI systems. Edge AI refers to...

UK Account-Hack Losses Increase 417% Amid New Reporting System Implementation

Reported losses associated with hacked email, social media, and other online accounts in the UK surged by 417% over the last financial year, reaching...