PT-2021-3925 · Microsoft · Mshtml+4

·

CVE-2021-40444

·

Published

2021-09-07

·

Updated

2026-06-24

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:N/C:P/I:C/A:P
Name of the Vulnerable Software and Affected Versions Microsoft MSHTML (affected versions not specified)
Description A remote code execution issue exists in the MSHTML browser rendering engine used by Microsoft Windows and Microsoft Office. The flaw is caused by incorrect code generation management. A remote attacker can exploit this by crafting a malicious ActiveX control embedded within a specially designed Microsoft Office document. When a user is convinced to open the document, the attacker can execute arbitrary code on the system. Users with administrative rights are more significantly impacted than those with limited user rights. Real-world exploitation has been observed in targeted attacks, including the deployment of "MerkSpy" spyware and activities by state-sponsored groups such as APT 35 (Magic Hound) and APT 28 (Fancy Bear). Some attack chains have utilized distorted RAR archives containing Windows Script Host scripts to deliver the malicious Word documents.
Recommendations Install the security updates released on September 14, 2021, immediately. For enterprise customers managing updates, deploy Microsoft Defender detection build 1.349.22.0 or newer. Keep antimalware products up to date to ensure detection and protection.

Exploit

Fix

DoS

RCE

Code Injection

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04442
CVE-2021-40444
OPENSUSE-SU-2024:13674-1

Affected Products

Bitdefender Antivirus
Defender For Endpoint
Mshtml
Office
Windows