PT-2021-3925 · Microsoft · Mshtml+4
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:N/C:P/I:C/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft MSHTML (affected versions not specified)
Description
A remote code execution issue exists in the MSHTML browser rendering engine used by Microsoft Windows and Microsoft Office. The flaw is caused by incorrect code generation management. A remote attacker can exploit this by crafting a malicious ActiveX control embedded within a specially designed Microsoft Office document. When a user is convinced to open the document, the attacker can execute arbitrary code on the system. Users with administrative rights are more significantly impacted than those with limited user rights. Real-world exploitation has been observed in targeted attacks, including the deployment of "MerkSpy" spyware and activities by state-sponsored groups such as APT 35 (Magic Hound) and APT 28 (Fancy Bear). Some attack chains have utilized distorted RAR archives containing Windows Script Host scripts to deliver the malicious Word documents.
Recommendations
Install the security updates released on September 14, 2021, immediately.
For enterprise customers managing updates, deploy Microsoft Defender detection build 1.349.22.0 or newer.
Keep antimalware products up to date to ensure detection and protection.
Exploit
Fix
DoS
RCE
Code Injection
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bitdefender Antivirus
Defender For Endpoint
Mshtml
Office
Windows