Security features bypass in Microsoft products - CVE-2024-30040
Published: May 14, 2024
Microsoft Internet Explorer
Windows
Windows Server
Microsoft
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to improper input validation within the Windows MSHTML Platform. A remote attacker can trick the victim to open or load a specially crafted file, bypass OLE mitigations in Microsoft 365 and Microsoft Office and execute arbitrary code on the system.
Note, the vulnerability is being actively exploited in the wild.