Microsoft under fire for mishandling critical CVE-2024-38112 zero-day vulnerability disclosure by ZDI
Microsoft is facing criticism from security researchers over its handling of a recently patched zero-day vulnerability. The controversy centers around CVE-2024-38112, a flaw in the MSHTML (Trident) rendering engine that was actively exploited by threat actors before being patched in July 2024’s Patch Tuesday update.