⚡ Exploit-DB.ai HIGH
HIGH

CVE-2024-38112

Published: March 18, 2026 · Source: National Vulnerability Database (NVD)

⚡ AI Threat Assessment

Windows MSHTML zero-day exploited by Void Banshee APT to steal data from financial and government targets. Apply July 2024 patches. Block .url file attachments at email gateway as immediate compensating control.

📋 Official Description

Windows MSHTML Platform Spoofing Vulnerability exploited by APT groups using specially crafted .url files to achieve code execution without user clicking on malicious links.

Get Real-Time CVE Alerts

Supernova subscribers receive AI-triaged CVE alerts the moment they're published — before the PoC drops.

Start Supernova — $99/mo →