U1 News
  • Home
  • World
  • U.S.
  • Business
  • Technology
  • Science
  • Entertainment
  • Sport
  • Health
Global News

Israel targets Hezbollah commander in Beirut strike after deadly Golan Heights attack

July 30, 2024

Taylor Swift speaks out after Southport mass stabbing at dance class

July 30, 2024

3 girls killed in stabbing at Taylor Swift-themed UK dance class. 7 people still critically wounded

July 30, 2024
Facebook Twitter Instagram
Trending
  • Simon Cowell says he's ‘aging backwards’ thanks to controversial blood-rinsing procedure
  • Alzheimer's risk could rise with common condition affecting millions, study finds
  • Simple nightly habit linked to healthier blood pressure, study suggests
  • Viral 'all-white' wellness push could boost mental health — here are 4 essentials to consider
  • Scientists reveal the one practice that could prevent dementia as you age
  • Weight-loss drugs could become unavailable for millions in coming years
  • Lower dementia risk linked to routine vaccination in major new analysis
  • Popular daily snack found to boost brain blood flow in older adults, new study shows
Friday, December 5
U1 News
  • Home
  • World

    Israel targets Hezbollah commander in Beirut strike after deadly Golan Heights attack

    July 30, 2024

    Taylor Swift speaks out after Southport mass stabbing at dance class

    July 30, 2024

    3 girls killed in stabbing at Taylor Swift-themed UK dance class. 7 people still critically wounded

    July 30, 2024

    Kerala, India, hit by landslides, killing at least 99

    July 30, 2024

    Taylor Swift ‘in shock’ after horrific UK stabbing, as police say 3rd child dies

    July 30, 2024
  • U.S.

    Biden criticises ‘extreme’ Supreme Court in push for reform

    July 30, 2024

    FBI details shooter’s search history before Trump assassination attempt

    July 30, 2024

    Reps. Mike Kelly, Jason Crow to lead task force on Trump rally shooting

    July 29, 2024

    Biden to call for major Supreme Court reforms, including term limits, at Civil Rights Act event Monday

    July 29, 2024

    Sonya Massey’s death revives pain for Breonna Taylor, Floyd activists

    July 29, 2024
  • Business

    AMD stock jumps on earnings beat driven by AI chip sales

    July 30, 2024

    Amazon is responsible for dangerous products sold on its site, federal agency rules

    July 30, 2024

    Microsoft investigating new outages of services after global CrowdStrike chaos

    July 30, 2024

    S&P 500, Nasdaq Tumble as Chip Stocks Slide Ahead of Big Tech Earnings

    July 30, 2024

    American consumers feeling more confident in July as expectations of future improve

    July 30, 2024
  • Technology

    Apple says Safari protects your privacy. We fact checked those claims.

    July 30, 2024

    GameStop Dunks On Xbox 360 Store Closing And Gets Savaged

    July 30, 2024

    Logitech has an idea for a “forever mouse” that requires a subscription

    July 30, 2024

    Friend: a new digital companion for the AI age

    July 30, 2024

    London Sports Mod Community Devolves Into War

    July 30, 2024
  • Science

    NASA’s Lunar Gateway has a big visiting vehicles problem

    August 1, 2024

    Boeing’s Cursed ISS Mission May Finally Make It Back to Earth

    July 30, 2024

    Should you floss before or after you brush your teeth?

    July 30, 2024

    Ancient swimming sea bug ‘taco’ had mandibles, new fossils show

    July 30, 2024

    NASA’s DART asteroid impact mission revealed ages of twin space rock targets (images)

    July 30, 2024
  • Entertainment

    Richard Gadd Backs Netflix to Get ‘Baby Reindeer’ Lawsuit Dismissed

    July 30, 2024

    Batman: Caped Crusader review: a pulpy throwback to DC’s Golden Age

    July 30, 2024

    Channing Tatum Praises Ryan Reynolds For Taking Gamble On Gambit

    July 30, 2024

    ‘Star Wars Outlaws’ somehow made me fall in love with Star Wars again

    July 30, 2024

    Great Scott and O’Brien’s Pub find new life in Allston

    July 30, 2024
  • Sport

    How Snoop Dogg became a fixture of the Paris Olympics

    July 30, 2024

    Team USA’s Coco Gauff exits Olympics singles tournament with a third-round loss : NPR

    July 30, 2024

    French police investigating abuse targeting Olympic opening ceremony DJ over ‘Last Supper’ scene

    July 30, 2024

    French DJ Takes Legal Action

    July 30, 2024

    Why BYU’s Jimmer Fredette is at the 2024 Paris Olympics

    July 30, 2024
  • Health

    Simon Cowell says he's ‘aging backwards’ thanks to controversial blood-rinsing procedure

    December 5, 2025

    Alzheimer's risk could rise with common condition affecting millions, study finds

    December 5, 2025

    Simple nightly habit linked to healthier blood pressure, study suggests

    December 4, 2025

    Viral 'all-white' wellness push could boost mental health — here are 4 essentials to consider

    December 4, 2025

    Scientists reveal the one practice that could prevent dementia as you age

    December 4, 2025
U1 News
Home»Technology»Windows MSHTML zero-day used in malware attacks for over a year
Technology

Windows MSHTML zero-day used in malware attacks for over a year

u1news-staffBy u1news-staffJuly 10, 2024No Comments4 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Windows.jpg
Share
Facebook Twitter LinkedIn Pinterest Email

Microsoft has fixed a zero-day Windows vulnerability that had been actively exploited in attacks for 18 months to launch malicious scripts while circumventing built-in security features.

This defect is CVE-2024-38112is a major problem with MHTML spoofing, July 2024 Patch Tuesday Security Updates.


Haifei Li of Check Point Research discovered the vulnerability and disclosed it to Microsoft in May 2024.

but, Report by LiThe researchers note that they have found samples exploiting this flaw dating back to January 2023.

Internet Explorer is gone, but not really gone

Haifei Li found that threat actors are distributing Windows Internet shortcut files (.url) to disguise themselves as legitimate files, such as PDFs, and then download and launch HTA files to install malware that steals passwords.

An Internet Shortcut file is a text file that contains various configuration settings such as which icon to display, which link to open when double-clicked, etc. If you save it as a .url file and double-click it, Windows will open the configured URL in your default web browser.

However, threat actors have discovered that they can force Internet Explorer to open specific URLs by: mhtml: URI handlers in URL directives, as shown below.

URL File Contents
Source: Checkpoint

MHTML is a “MIME Encapsulation of Aggregate HTML Documents” file, a technology introduced in Internet Explorer that encapsulates an entire webpage, including images, into a single archive.

If the URL is mhtml: For URIs, Windows will automatically launch Internet Explorer instead of the default browser.

According to vulnerability researcher Will Dorman, opening web pages in Internet Explorer provides an added benefit to threat actors, as it results in fewer security warnings when downloading malicious files.

“First, IE allows .HTA files to be downloaded from the Internet without warning you.” Dolman explained. On Mastodon.

“Then, once downloaded, the .HTA file is stored in the INetCache directory, but without an explicit MotW. At this point, the only protection the user has is a warning that a ‘website’ is trying to open web content using a program on their computer.”

“If the user believes they trust ‘this’ website, without saying which website, the code will be executed.”

Essentially, the threat actors are taking advantage of the fact that Windows 10 and Windows 11 still include Internet Explorer by default.

Despite Microsoft Announces retirement Although Edge replaced it with all practical functionality about two years ago, the outdated browser can still be invoked and exploited for malicious purposes.

According to Check Point, the threat actors are creating internet shortcut files with icon indexes that appear as links to PDF files.

When clicked, the specified web page opens in Internet Explorer and automatically attempts to download a file that appears to be a PDF file but is actually an HTA file.

Internet Explorer downloads HTA files disguised as PDFs
Source: Checkpoint

However, the threat actor can hide the HTA extension and make it appear as if a PDF is being downloaded by embedding Unicode characters in the filename to hide the .hta extension, as shown below.

HTA files that use Unicode character padding to hide the .hta extension
Source: BleepingComputer

When Internet Explorer downloads an HTA file, it will ask if it wants to save or open it, and if a user tries to open it thinking it’s a PDF, because it doesn’t contain the Webmark, they will only see a generic warning that content is being opened from a website.

Windows displays a warning when Internet Explorer launches an HTA file
Source: BleepingComputer

Because the target expects to download a PDF, the user trusts the alert and the file is allowed to run.

Check Point Research has found that if you allow an HTA file to run, Atlantida Stealer malware Password-stealing malware on your computer.

Once the malware is executed, it steals all the credentials stored in your browsers, cookies, browser history, cryptocurrency wallets, Steam credentials, and other sensitive data.

Microsoft has fixed the CVE-2024-38112 vulnerability, mhtml: Because the URI comes from Internet Explorer, it will now open in Microsoft Edge instead.

CVE-2024-38112 is CVE-2021-40444North Korean hackers exploited a zero-day vulnerability in MHTML to Attacks targeting security researchers in 2021.

attacks malware MSHTML Windows Year zeroday
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
u1news-staff
u1news-staff
  • Website

Related Posts

Kennedy sharpens vaccine attacks, without scientific backing

November 24, 2025

Treating gum disease could reduce risk of heart attacks and strokes, study suggests

November 8, 2025

Hidden infection kills millions of children each year as doctors warn of overlooked symptoms

October 5, 2025

Hidden causes of heart attacks often overlooked or misdiagnosed, study finds

September 23, 2025
Add A Comment

Leave A Reply Cancel Reply

Latest Posts

Simon Cowell says he's ‘aging backwards’ thanks to controversial blood-rinsing procedure

December 5, 2025

Alzheimer's risk could rise with common condition affecting millions, study finds

December 5, 2025

Simple nightly habit linked to healthier blood pressure, study suggests

December 4, 2025

Viral 'all-white' wellness push could boost mental health — here are 4 essentials to consider

December 4, 2025
Unites States

Biden criticises ‘extreme’ Supreme Court in push for reform

July 30, 2024

FBI details shooter’s search history before Trump assassination attempt

July 30, 2024

Reps. Mike Kelly, Jason Crow to lead task force on Trump rally shooting

July 29, 2024

Subscribe to Updates

Get the latest sports news from SportsSite about soccer, football and tennis.

Copyright ©️ All rights reserved. | U1 News
  • Home
  • About Us
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.