Summary:
-
Check Point Research identified a critical zero-day spoofing attack exploiting Microsoft Internet Explorer on Windows 10/11 systems, known as CVE-2024-38112.
-
The vulnerability allows attackers to execute remote code by tricking users into opening malicious Internet Shortcut (.url) files, active for over a year.
-
Attackers use a trick to mask the malicious .hta extension, leveraging outdated Internet Explorer security to compromise updated Windows systems.
!