A recently fixed vulnerability in Windows known as the “MSHTML spoofing vulnerability” and tracked under CVE-2024-43461 has now been flagged as previously exploited. This vulnerability was used by APT hacker group Void Banshee in attacks to install malware that steals information.

Important findings

  • The CVE-2024-43461 vulnerability was exploited in attacks by Void Banshee.
  • The attacks were aimed at stealing information and making financial profit.
  • The vulnerability was originally announced in September 2024 as part of Microsoft’s Patch Tuesday.
  • The attacks also used another vulnerability known as CVE-2024-38112.

The discovery of the CVE-2024-43461 vulnerability was attributed to Peter Girnus, a senior threat researcher at Trend Micro. Girnus explained that the vulnerability in zero-day attacks was used by Void Banshee to steal information.

Details about the attacks

In July, Check Point Research and Trend Micro reported attacks that exploited Windows Zero Days to infect devices with the Atlantida Info stealer. This malware has been used to steal passwords, authentication cookies and cryptocurrency wallets from infected devices.

The attacks used the zero-days CVE-2024-38112 (fixed in July) and CVE-2024-43461 (fixed this month) as part of the attack structure.

The discovery of the CVE-2024-38112 vulnerability was attributed to Haifei Li from Check Point Research. Li explained that the attackers used special Windows internet shortcut files (.url extension) that opened Internet Explorer instead of Microsoft Edge when clicked to visit the malicious URL.

The Role of Braille Spaces

The CVE-2024-43461 vulnerability was also used in Void Banshee attacks to create a CWE-451 condition through HTA filenames containing 26 encoded Braille spaces (%E2%A0%80) to hide the .hta extension.

An example of such a filename could look like this:

When Windows opened this file, the Braille spaces pushed the HTA extension outside the user interface, so it was indicated only by a “…” string in the Windows prompts. This made the HTA files look like PDF files, increasing the likelihood that users would open them.

Security Updates and Future Actions

After installing the security update for CVE-2024-43461, Windows now displays the actual .hta extension in the prompts. However, Girnus notes that the included spaces could still confuse users into thinking the file is a PDF.

Microsoft also fixed 3 other actively exploited zero-days in the September patch Tuesday, including CVE-2024-38217, which was used in LNK stomping attacks to bypass the Mark of the Web security feature.

Sources

  • Windows vulnerability abused braille “spaces” in zero-day attacks, BleepingComputer.