---
id: CVE-2024-30040
title: Windows MSHTML Platform Security Feature Bypass Vulnerability
summary: Windows MSHTML Platform Security Feature Bypass Vulnerability
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C'
cvssSource: cna
cwe:
  - CWE-20
vendor: Microsoft
product: Windows 10 Version 1809
affected:
  - windows_10_version_1809 >= 10.0.17763.0 < 10.0.17763.5820
  - windows_10_version_1809 >= 10.0.0 < 10.0.17763.5820
  - windows_server_2019 >= 10.0.17763.0 < 10.0.17763.5820
  - >-
    windows_server_2019_server_core_installation >= 10.0.17763.0 <
    10.0.17763.5820
  - windows_server_2022 >= 10.0.20348.0 < 10.0.20348.2461
  - windows_11_version_21h2 >= 10.0.0 < 10.0.22000.2960
  - windows_10_version_21h2 >= 10.0.19043.0 < 10.0.19044.4412
  - windows_11_version_22h2 >= 10.0.22621.0 < 10.0.22621.3593
  - windows_10_version_22h2 >= 10.0.19045.0 < 10.0.19045.4412
  - windows_11_version_22h3 >= 10.0.22631.0 < 10.0.22631.3593
  - windows_11_version_23h2 >= 10.0.22631.0 < 10.0.22631.3593
  - >-
    windows_server_2022_23h2_edition_server_core_installation >= 10.0.25398.0 <
    10.0.25398.887
  - windows_10_version_1507 >= 10.0.10240.0 < 10.0.10240.20651
  - windows_10_version_1607 >= 10.0.14393.0 < 10.0.14393.6981
  - windows_server_2016 >= 10.0.14393.0 < 10.0.14393.6981
  - >-
    windows_server_2016_server_core_installation >= 10.0.14393.0 <
    10.0.14393.6981
ssvc:
  exploitation: active
  automatable: 'no'
  technicalImpact: total
  timestamp: '2025-01-28T16:39:27.396579Z'
exploited: true
exploitAvailable: true
published: '2024-05-14'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T17:48:34.568Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2024-30040'
references:
  - url: 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30040'
    label: Windows MSHTML Platform Security Feature Bypass Vulnerability
tags:
  - cve.org
  - in-the-wild
  - exploit-available
  - kev
epss: 0.03939
epssPercentile: 0.90107
kev: true
kevDateAdded: '2024-05-14'
kevDueDate: '2024-06-04'
kevRansomware: false
zeroDay: true
ingestedAt: '2026-10-07T18:42:20.912Z'
---

## Overview

Windows MSHTML Platform Security Feature Bypass Vulnerability

## Affected

- `windows_10_version_1809 >= 10.0.17763.0 < 10.0.17763.5820`
- `windows_10_version_1809 >= 10.0.0 < 10.0.17763.5820`
- `windows_server_2019 >= 10.0.17763.0 < 10.0.17763.5820`
- `windows_server_2019_server_core_installation >= 10.0.17763.0 < 10.0.17763.5820`
- `windows_server_2022 >= 10.0.20348.0 < 10.0.20348.2461`
- `windows_11_version_21h2 >= 10.0.0 < 10.0.22000.2960`
- `windows_10_version_21h2 >= 10.0.19043.0 < 10.0.19044.4412`
- `windows_11_version_22h2 >= 10.0.22621.0 < 10.0.22621.3593`
- `windows_10_version_22h2 >= 10.0.19045.0 < 10.0.19045.4412`
- `windows_11_version_22h3 >= 10.0.22631.0 < 10.0.22631.3593`
- `windows_11_version_23h2 >= 10.0.22631.0 < 10.0.22631.3593`
- `windows_server_2022_23h2_edition_server_core_installation >= 10.0.25398.0 < 10.0.25398.887`
- `windows_10_version_1507 >= 10.0.10240.0 < 10.0.10240.20651`
- `windows_10_version_1607 >= 10.0.14393.0 < 10.0.14393.6981`
- `windows_server_2016 >= 10.0.14393.0 < 10.0.14393.6981`
- `windows_server_2016_server_core_installation >= 10.0.14393.0 < 10.0.14393.6981`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
