CISA KEV · catalog date Sep 16, 2024 · first observed Jul 19, 2026
Evidence dossier
CVE-2024-43461
Windows MSHTML Platform Spoofing Vulnerability
Exploited in the wild (CISA KEV since Sep 16, 2024). microsoft reports CVSS 3.1 8.8. EPSS estimates 54.5% exploit likelihood as of Aug 26, 2026.
As of Aug 27, 2026
Normalized restatement
Windows MSHTML Platform Spoofing Vulnerability
- State
- PUBLISHED
- Published
- Sep 10, 2024
- Updated
- Dec 30, 2025
- Evidence coverage
- 92%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCAmicrosoftOriginal evidence ↗
Record text: Windows MSHTML Platform Spoofing Vulnerability
Inspect raw assertion
- Field
container- Value
- Windows MSHTML Platform Spoofing Vulnerability
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Microsoft Windows MSHTML Platform Spoofing Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Microsoft Windows MSHTML Platform Spoofing Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 54.49% probability · 98.94th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.544860000000; percentile 0.989350000000
FIRST EPSS · score date Aug 26, 2026 · 98.9th percentile · first observed Aug 26, 2026
microsoft · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
Windows MSHTML Platform Spoofing Vulnerability
Inspect raw assertion
- Field
container- Value
- Windows MSHTML Platform Spoofing Vulnerability
Microsoft Windows MSHTML Platform Spoofing Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Microsoft Windows MSHTML Platform Spoofing Vulnerability
54.49% probability · 98.94th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.544860000000; percentile 0.989350000000
Applicability
Cited product scope
Grouped from 1 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
40 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.10240.0", "lessThan": "10.0.10240.20766", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.14393.0", "lessThan": "10.0.14393.7336", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.17763.0", "lessThan": "10.0.17763.6293", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.19043.0", "lessThan": "10.0.19044.4894", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.19045.0", "lessThan": "10.0.19045.4894", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.0", "lessThan": "10.0.22000.3197", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.22621.0", "lessThan": "10.0.22621.4169", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.22631.0", "lessThan": "10.0.22631.4169", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.22631.0", "lessThan": "10.0.22631.4169", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.26100.0", "lessThan": "10.0.26100.1742", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.1.7601.0", "lessThan": "6.1.7601.27320", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.1.7601.0", "lessThan": "6.1.7601.27320", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.0.6003.0", "lessThan": "6.0.6003.22870", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.0.6003.0", "lessThan": "6.0.6003.22870", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.0.6003.0", "lessThan": "6.0.6003.22870", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.2.9200.0", "lessThan": "6.2.9200.25073", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.3.9600.0", "lessThan": "6.3.9600.22175", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.3.9600.0", "lessThan": "6.3.9600.22175", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.2.9200.0", "lessThan": "6.2.9200.25073", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.14393.0", "lessThan": "10.0.14393.7336", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.14393.0", "lessThan": "10.0.14393.7336", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.17763.0", "lessThan": "10.0.17763.6293", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.17763.0", "lessThan": "10.0.17763.6293", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.20348.0", "lessThan": "10.0.20348.2700", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.25398.0", "lessThan": "10.0.25398.1128", "versionType": "custom"}]Affected-product evidence
Accepted scope and product mapping
15 canonical links · 1 source-reported links
vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-026201767813843a6d53867bacde4a55c3035cb868c0a72434012c5e30dab148
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
2364ecb2-ca07-4890-a655-33b03306147d44a4cfed-6a45-4ac7-a989-c6f911097ae3vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-02e254d111ce604757a15650ef469f4f8365d6247da82ce3ac2695c3cfc7dc5f
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
c66d9224-b47a-4141-b3cb-2a6256a1ec6dvendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-217b1ab3d25f361a639824f86753d418b35aa2a816ee370bb71b5d1dd883d87a
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
2930c3b9-c774-4271-aa3e-602cf25fb22b800f65de-1916-4f07-a11b-959768fe7764903d20a3-9c9d-42e2-b600-cac39e903448vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-25a2932c0bbcb648f7e391c8b9d34c734e5085444c03c1c206b9d4c4baa80b25
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
01d7cac0-a734-4c3e-9880-ac64ad025a70vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-5a80416e92fed0cddbb3d4f3840218b448dee11159824ad25a0353da566963fe
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
4dcae027-0995-422c-ab6f-0981c92601dcfe4cb1b2-0bbb-4880-b6e3-a8a94febbad6vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-740fec3e9838b5eabe76ebe27e4d0d7a4cb2e0ef7e13923300d3d0b51e3fce1c
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
094e2ab9-0433-456b-8d5f-4bd9e0489569f84dda57-6d0c-4229-873c-5620117c5092vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-7fe28b5b5b17e017d9554204df059dd619746ffb5c80da87bcbfb1c52720d2f4
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
f5c320df-f27a-47cd-b56a-dfccbbf72622vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-8665879a2f5fe8b8eab868c43d6ace340b95d1f3879639d97ebdf60ef7b49b5f
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
f402c841-624d-43c0-9128-8b14bf2abc43vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-9851bd571b8ab08bca589cd73710badfef557d036f0fb7707f694f1c9f597cb4
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
a1fa36e0-e837-469e-b5dc-42907bd0bdf2fc4213e5-1f56-4408-a523-e08cb1ffd2dfvendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-a3084138383423221f61594e86f5b295e5e254acd7ae5284f45e0877a084db43
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
100fd8b1-2a2c-4917-b326-233a4aaaa426vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-a6295b9daad3ca57ce70751badba5b7fe99229c8a562cc7400e8cfef3daccaee
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
1601f4a2-5ed7-4fac-97cb-0bb429e730359b130dd9-676e-4659-8070-3f35fef74d78cf1bde15-1ff2-4ee0-9b94-1b16e4c415e3vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-bc66b50eed682b3633d0f3a2914725d0a72d6d0d5fece14f566d91bc87448c0b
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
a753e938-f5c5-4a22-8565-fe5f2769799fvendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-d196d31962e613955a91e33e795c22dcfa7bf25173abebaca616a6350cce9ce1
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
878a9847-e072-4953-b615-22da99a25f1evendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-ec10c9f400f23fdf118887f60fe116ffde4adb76dcf118cdd3a7556fd033da3b
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
4dc10aff-0429-4cf5-bd23-4247d6347abfvendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-f8c509b6ec25f2a4338a23556be321da5a7c3e8da9f1a4c52f7f15dd0e9a0d2a
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
85a42ad0-fe95-45c7-900e-c2a6cd99a2daCanonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 25
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0433d7f2-b33c-4736-80d3-e7e288a0df1a31f7041f-2a12-4fc6-ae31-e0196469fb915ce32f2f-f5a3-4cd8-9b36-1d669cf3b03763c38f0c-14ba-4c6f-aad3-f54507f106cc6d701adb-745f-4d1d-a41d-cbf7efeec5026e6a17c1-88e0-46b0-bbab-4833b9cb4cda72fc7597-af6b-43c7-8d36-4816f0b746a474a3ed8d-648b-4f2a-abec-4f943a89e20f75acbb43-6113-4d22-a892-0ff07580c90882a24d93-4d59-4972-a9c4-1942511580f0863cdb5c-63fd-4f88-9e2a-5c773e90a1409391683a-2ce7-45ed-a4b5-6a54485d348197018ce9-c5b8-4a1b-b88c-6ae1672181389b6203a2-b04e-40fc-8964-fe3aaab4d2c19e48d97f-d06f-441d-846a-c1b190275a6caa296139-b940-4f69-9c9d-c762e7e11bc7affd1919-9754-46a3-88d7-bcba50fca461b776361e-407b-49a8-840d-cf1b14cbefffb8543784-c7a6-4fd5-88fa-795a5ebba9abc0e8df83-b7df-4cd6-b7bc-b0c71f4c226cc954bebe-09b1-4339-b42e-dc1df08939e0ca374612-3607-4e15-87b7-b527facaf27bdf91aa9a-eaad-45a4-804c-7abfc73fa8d2f609b016-6e50-464d-8c25-91cb93803d7ffe842575-e420-43da-ba0d-200d75263fc4Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:CDirect CVE/CNA normalized decisions
microsoft
CVSS 3.1 · Primary · Original assertion · rank 1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C- Validation
- Valid match
- Recomputed
- 8.8
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.