CVE-2024-38178CISA KEV
Microsoft Windows Scripting Engine Memory Corruption Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft Windows Scripting Engine contains a memory corruption vulnerability that allows unauthenticated attacker to initiate remote code execution via a specially crafted URL.
- Product
- Windows
- Added to KEV
- 13 Aug 2024
- Federal remediation due
- 3 Sep 2024
- Known ransomware use
- Not reported