Security firm Avast observed attacks last year and developed a proof-of-concept (PoC) exploit and sent it to Microsoft in August 2023. It took Microsoft six months to make a patch (until February 2024) and didn’t mark it as a zero day in Microsoft Vulnerability Management.