Vulnerability record

CVE-2021-40444

Microsoft MSHTML Remote Code Execution Vulnerability

Severity: HighExploitation: Exploitation confirmedCISA KEV Used by ransomware
What should I do?

This vulnerability is in the CISA Known Exploited Vulnerabilities catalog: attackers are using it. If you run MSHTML, fix it now.

CISA required action: Apply updates per vendor instructions.

US federal civilian agencies must remediate by Nov 17, 2021.

Patch status

Official fix available since

Apply the vendor's update to every affected system. Check the fixed-in versions below where known.

Basis: NVD patch reference

Description

Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using specially-crafted Microsoft Office documents. An attacker could craft a malicious ActiveX control to be used by a Microsoft Office document that hosts the browser rendering engine. The attacker would then have to convince the user to open the malicious document. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Microsoft Defender Antivirus and Microsoft Defender for Endpoint both provide detection and protections for the known vulnerability. Customers should keep antimalware products up to date. Customers who utilize automatic updates do not need to take additional action. Enterprise customers who manage updates should select the detection build 1.349.22.0 or newer and deploy it across their environments. Microsoft Defender for Endpoint alerts will be displayed as: “Suspicious Cpl File Execution”. Upon completion of this investigation, Microsoft will take the appropriate action to help protect our customers. This may include providing a security update through our monthly release process or providing an out-of-cycle security update, depending on customer needs. Please see the Mitigations and Workaround sections for important information about steps you can take to protect your system from this vulnerability. UPDATE September 14, 2021: Microsoft has released security updates to address this vulnerability. Please see the Security Updates table for the applicable update for your system. We recommend that you install these updates immediately. Please see the FAQ for important information about which updates are applicable to your system.

Source: NIST National Vulnerability Database. Official vulnerability data, reproduced as published.

Affected products

Products affected by this vulnerability, with versions and the source of each entry
ProductVendorSource
MSHTMLMicrosoftKEV

Sources: KEV = CISA Known Exploited Vulnerabilities catalog. Version details have not been published yet.

Intelligence timeline

Developments from the last 30 days, newest first.

  1. CVSS scoredUpdateKEV

    CVE-2021-40444 scored CVSS 8.8: Microsoft MSHTML, Microsoft MSHTML Remote Code Execution Vulnerability

    CISA lists this as exploited in the wild and known to be used in ransomware campaigns. Unpatched MSHTML systems are exposed to active attacks now.

    Basis: NIST National Vulnerability Database

  2. Patch releasedUpdateKEV

    Patch released for CVE-2021-40444: Microsoft MSHTML, Microsoft MSHTML Remote Code Execution Vulnerability

    An official fix is now available for Microsoft MSHTML. This vulnerability is being exploited, so apply it promptly.

    Basis: NVD patch reference

1 earlier event is available with a subscription. See plans.

Coverage

We have not published a story about this vulnerability yet.

References

  • nvd.nist.gov https://nvd.nist.gov/vuln/detail/CVE-2021-40444
  • msrc.microsoft.com https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40444
  • packetstormsecurity.com http://packetstormsecurity.com/files/164210/Microsoft-Windows-MSHTML-Overview.html
  • packetstormsecurity.com http://packetstormsecurity.com/files/165214/Microsoft-Office-Word-MSHTML-Remote-Code-Execution.html
  • packetstormsecurity.com http://packetstormsecurity.com/files/167317/Microsoft-Office-MSDT-Follina-Proof-Of-Concept.html
  • portal.msrc.microsoft.com https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40444
  • cisa.gov https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-40444