CISA Known Exploited Vulnerability (KEV)
Microsoft Windows MSHTML Platform Spoofing Vulnerability
October 8, 2024
October 29, 2024
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Description
Windows MSHTML Platform Spoofing Vulnerability
Weakness Enumeration
CWE-ID | CWE Name |
---|---|
CWE-79 |
Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) |