CVE-2024-38112

Exploited in the Wild ✓ Confirmed 0-Day
Triaged: March 5, 2026 11 articles

EPSS Score

Source: FIRST.org · 2026-05-24
92.96%
probability
This CVE has a 92.96% probability of being exploited in the next 30 days.
0% Top 99.8th percentile of all CVEs 100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE. View on VulnerabilityLookup ↗

Attack Intelligence

Signal Intelligence

Confidence
92%
EPSS 92.96%
Mentions 11
Last Seen Sep 16, 2024

CNA Information

Analyst Note

CVE-2024-38112 explicitly identified as a zero-day in multiple authoritative sources (BleepingComputer articles explicitly state 'zero-day attacks' and 'MSHTML zero-day'). Exploitation documented in the wild over an extended period before the July 2024 patch, meeting the core zero-day criteria of in-the-wild exploitation preceding patch availability.

Threat Actors 19

MuddyWater
apt_group Information theft and espionage 🇮🇷 IR
Lazarus Group
apt_group Information theft and espionage 🇰🇵 KP
APT 29
apt_group Information theft and espionage 🇷🇺 RU
Cobalt
apt_group Financial crime 🇷🇺 RU
APT37
apt_group Information theft and espionage 🇰🇵 KP
APT 28
apt_group Information theft and espionage 🇷🇺 RU
Kimsuky
apt_group Information theft and espionage 🇰🇷 KR
CHRYSENE
apt_group Information theft and espionage 🇮🇷 IR
UAC-0020
apt_group 🇺🇦 UA
Infy
apt_group Information theft and espionage 🇮🇷 IR
SideWinder
apt_group 🇮🇳 IN
RAZOR TIGER
apt_group Information theft and espionage 🇮🇳 IN
Larva-208
apt_group 🇷🇺 RU
APT 22
apt_group Information theft and espionage 🇨🇳 CN
Void Banshee
apt_group unknown
TA571
apt_group 🇷🇺 RU
The White Company
apt_group Information theft and espionage 🇨🇳 CN
Mana Team
apt_group 🇨🇳 CN
APT 5
apt_group Information theft and espionage 🇨🇳 CN

Triage Info

Decided atMar 05, 2026