PT-2021-3925 · Microsoft · Defender For Endpoint+4
Bryce Abdo
+4
·
Published
2021-09-07
·
Updated
2026-03-10
·
CVE-2021-40444
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:N/C:P/I:C/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft MSHTML (affected versions not specified)
Description
The vulnerability in Microsoft MSHTML allows remote attackers to execute arbitrary code by using specially crafted Microsoft Office documents. An attacker could craft a malicious ActiveX control to be used by a Microsoft Office document that hosts the browser rendering engine. The attacker would then have to convince the user to open the malicious document. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Microsoft Defender Antivirus and Microsoft Defender for Endpoint provide detection and protections for the known vulnerability. The vulnerability has been exploited in targeted attacks, and it is recommended to keep antimalware products up to date.
Recommendations
To resolve the issue, update Microsoft MSHTML to the latest version.
As a temporary workaround, consider disabling the use of ActiveX controls in Microsoft Office documents until a patch is available.
Restrict access to the MSHTML engine to minimize the risk of exploitation.
Avoid using Microsoft Office documents from untrusted sources until the issue is resolved.
Keep antimalware products up to date, and deploy the latest detection build across environments.
Apply the security updates provided by Microsoft to address this vulnerability.
Exploit
Fix
RCE
Code Injection
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bitdefender Antivirus
Defender For Endpoint
Mshtml
Office
Windows