CVE-2021-40444KEV · OVERDUECWE-22path-traversal

Microsoft MSHTML Remote Code Execution Vulnerability

High · published September 15, 2021

Patch now

Confirmed exploited, and the score agrees

CVSS calls it high at 8.8. It is confirmed in active exploitation. It sits in the 99.9th percentile for exploit probability.

1754
days past CISA
deadline
CVSS v3.1
8.8
EPSS
97%
Percentile
99.9
In the wild
Confirmed
What it is

🚨 A cleverly crafted Microsoft Office document is all it takes to exploit this remote code execution vulnerability in MSHTML! ⚡ Think of it as a delivery driver handing over a package that looks perfectly normal, but inside is a sneaky surprise that can wreak havoc once opened. Similar to how one deceptive parcel can cause chaos at your doorstep, this vulnerability can let attackers execute harmful code on your system. An attacker could gain full control over your machine just by tricking you into opening a malicious document. For users with administrative rights, this could lead to devastating implications, including data loss and system compromise. Even those with fewer rights could still face significant risks.

Put simply

Think of it as a delivery driver handing over a package that looks perfectly normal, but inside is a sneaky surprise that can wreak havoc once opened. Similar to how one deceptive parcel can cause chaos at your doorstep, this vulnerability can let attackers execute harmful code on your system. This vulnerability allows an attacker to use a malicious ActiveX control within a Microsoft Office document to execute arbitrary code on the host machine, leveraging the browser rendering engine embedded in MSHTML.

What to do

An attacker could gain full control over your machine just by tricking you into opening a malicious document. For users with administrative rights, this could lead to devastating implications, including data loss and system compromise. Even those with fewer rights could still face significant risks. To defend against this vulnerability, ensure Microsoft Defender Antivirus is up to date and that you've applied security updates released by Microsoft. Users should be cautious about opening unexpected documents and enterprise customers need to deploy the detection build 1.349.22.0 or newer across their environments. Patch immediately! You've got this! Stay vigilant, keep your defenses updated, and you'll be safeguarding your system in no time! 🛡️

The record
Technical detail
CVSS v3.1
8.8 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:L
CVSS v4.0
Not supplied
EPSS
0.97450 · 99.9th percentile
Weakness
CWE-22 · Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Published
2021-09-15T16:15Z
KEV added
2021-11-03 · due 2021-11-17
Affected products (19)
ProductVersionsFixed in
microsoft/windows_10_1507< 10.0.10240.1906010.0.10240.19060
microsoft/windows_10_1607< 10.0.14393.465110.0.14393.4651
microsoft/windows_10_1809< 10.0.17763.218310.0.17763.2183
microsoft/windows_10_1909< 10.0.18363.180110.0.18363.1801
microsoft/windows_10_2004< 10.0.19041.123710.0.19041.1237
microsoft/windows_10_20h2< 10.0.19042.123710.0.19042.1237
microsoft/windows_10_21h1< 10.0.19043.123710.0.19043.1237
microsoft/windows_7all versions
microsoft/windows_8.1all versions
microsoft/windows_rt_8.1all versions
microsoft/windows_server_2004< 10.0.19041.123710.0.19041.1237
microsoft/windows_server_2008all versions
microsoft/windows_server_2008all versions
microsoft/windows_server_2012all versions
microsoft/windows_server_2012all versions
microsoft/windows_server_2016< 10.0.14393.465110.0.14393.4651
microsoft/windows_server_2019< 10.0.17763.218310.0.17763.2183
microsoft/windows_server_2022< 10.0.20348.23010.0.20348.230
microsoft/windows_server_20h2< 10.0.19042.123710.0.19042.1237
References (6)
EPSS history
Timeline
  • 03 NOV 00:00Z
    Added to CISA KEV — remediate by Nov 17
    kev
  • 15 SEP 11:24Z
    Microsoft MSHTML Remote Code Execution Vulnerability
    cvelistv5