PT-2021-3925 · Microsoft · Defender For Endpoint+4

Bryce Abdo

+4

·

Published

2021-09-07

·

Updated

2026-03-10

·

CVE-2021-40444

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:N/C:P/I:C/A:P
Name of the Vulnerable Software and Affected Versions Microsoft MSHTML (affected versions not specified)
Description The vulnerability in Microsoft MSHTML allows remote attackers to execute arbitrary code by using specially crafted Microsoft Office documents. An attacker could craft a malicious ActiveX control to be used by a Microsoft Office document that hosts the browser rendering engine. The attacker would then have to convince the user to open the malicious document. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Microsoft Defender Antivirus and Microsoft Defender for Endpoint provide detection and protections for the known vulnerability. The vulnerability has been exploited in targeted attacks, and it is recommended to keep antimalware products up to date.
Recommendations To resolve the issue, update Microsoft MSHTML to the latest version. As a temporary workaround, consider disabling the use of ActiveX controls in Microsoft Office documents until a patch is available. Restrict access to the MSHTML engine to minimize the risk of exploitation. Avoid using Microsoft Office documents from untrusted sources until the issue is resolved. Keep antimalware products up to date, and deploy the latest detection build across environments. Apply the security updates provided by Microsoft to address this vulnerability.

Exploit

Fix

RCE

Code Injection

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2021-04442
CVE-2021-40444
OPENSUSE-SU-2024:13674-1

Affected Products

Bitdefender Antivirus
Defender For Endpoint
Mshtml
Office
Windows