Skip to main content

CVE detail

CVE-2021-40444

<p>Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using specially-crafted Microsoft Office documents.</p> <p>An attacker could craft a malicious ActiveX control to be used by a Microsoft Office document that hosts the browser rendering engine. The attacker would then have to convince the user to open the malicious document. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</p> <p>Microsoft Defender Antivirus and Microsoft Defender for Endpoint both provide detection and protections for the known vulnerability. Customers should keep antimalware products up to date. Customers who utilize automatic updates do not need to take additional action. Enterprise customers who manage updates should select the detection build 1.349.22.0 or newer and deploy it across their environments. Microsoft Defender for Endpoint alerts will be displayed as: “Suspicious Cpl File Execution”.</p> <p>Upon completion of this investigation, Microsoft will take the appropriate action to help protect our customers. This may include providing a security update through our monthly release process or providing an out-of-cycle security update, depending on customer needs.</p> <p>Please see the <strong>Mitigations</strong> and <strong>Workaround</strong> sections for important information about steps you can take to protect your system from this vulnerability.</p> <p><strong>UPDATE</strong> September 14, 2021: Microsoft has released security updates to address this vulnerability. Please see the Security Updates table for the applicable update for your system. We recommend that you install these updates immediately. Please see the FAQ for important information about which updates are applicable to your system.</p>

CVSS 8.8 · HighBuzz score 81.5KEV listed1 public exploit repository references

Buzz score

Why this CVE is surfacing

Buzz score total 81.5

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 19.0 · KEV 25.0 · OTX 0.0 · PoC 7.5
Mention score
30.0
53 evidence mentions in the snapshot
Diversity score
19.0
8 sources across 2 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
7.5
1 repos · best confidence 0.99
Best PoC traction
832
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
53 source links · newest first
  • Microsoft warns that a recently patched Windows flaw, tracked as CVE-2024-43461, was actively exploited as a zero-day before July 2024. Microsoft warns that attackers actively exploited the Windows vulnerability CVE-2024-43461 as a zero-day before July 2024. The vulnerability CVE-2024-43461 is a Windows MSHTML platform spoofing issue. MSHTML is a platform used by Internet Explorer. Although […]

    newssecurityaffairs.comSep 16, 2024, 1:56 PM
  • Void Banshee APT group exploited the Windows zero-day CVE-2024-38112 to execute code via the disabled Internet Explorer. An APT group tracked as Void Banshee was spotted exploiting the Windows zero-day CVE-2024-38112 (CVSS score of 7.5) to execute code through the disabled Internet Explorer. The vulnerability is a Windows MSHTML Platform Spoofing Vulnerability. Successful exploitation of […]

    newssecurityaffairs.comJul 17, 2024, 2:16 PM
  • An APT group has been exploiting a Windows vulnerability patched last week to trick users into downloading malicious files by unwittingly opening URLs in the retired Internet Explorer browser. The attack chain deploys information stealing malware and has been in use since May, when the flaw was still unknown to Microsoft. Researchers from Trend Micro, […]

    newswww.csoonline.comJul 17, 2024, 10:00 AM
  • by Haifei Li Introduction and Background Check Point Research recently discovered that threat actors have been using novel (or previously unknown) tricks to lure Windows users for remote code execution. Specifically, the attackers used special Windows Internet Shortcut files (.url extension name), which, when clicked, would call the retired Internet Explorer (IE) to visit the […]

    vendorresearch.checkpoint.comJul 9, 2024, 9:10 PM
  • Security Affairs Malware Newsletter – Round 1Security Affairs

    Today marks the launch of the Security Affairs newsletter, specializing in Malware. This newsletter complements the weekly one you already receive. Each week, it will feature a collection of the best articles and research on malware. CapraTube Remix | Transparent Tribe’s Android Spyware Targeting Gamers, Weapons Enthusiasts Supply Chain Compromise Leads to Trojanized Installers for […]

    newssecurityaffairs.comJul 7, 2024, 2:07 PM
  • A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. GootLoader is still active and efficient Hackers stole OpenAI secrets in a 2023 security breach Hackers leak 170k […]

    newssecurityaffairs.comJul 7, 2024, 9:14 AM
  • Russian state-backed hacking group Forest Blizzard (aka Fancy Bear, aka APT28) has been using a known Microsoft Outlook vulnerability (CVE-2023-23397) to target public and private entities in Poland, Polish Cyber Command has warned. Compromising email accounts and maintaining access to them APT28 is known for targeting government, non-governmental, energy and transportation organizations in the US, Europe, and the Middle East. The most recent attacks were detected and reported by the computer security incident response team … More →

    newswww.helpnetsecurity.comDec 5, 2023, 2:45 PM
  • Microsoft warns that the Russia-linked APT28 group is actively exploiting the CVE-2023-23397 Outlook flaw to hijack Microsoft Exchange accounts. Microsoft’s Threat Intelligence is warning of Russia-linked cyber-espionage group APT28 (aka “Forest Blizzard”, “Fancybear” or “Strontium”) actively exploiting the CVE-2023-23397 Outlook flaw to hijack Microsoft Exchange accounts and steal sensitive information. The APT28 group (aka Fancy Bear, Pawn Storm, Sofacy Group, Sednit, BlueDelta, […]

    newssecurityaffairs.comDec 5, 2023, 2:19 PM
  • In July 2023, pro-Russian APT Storm-0978 targeted support for Ukrainian NATO admission with an exploit chain. Analysis of it reveals the new CVE-2023-36584.

    vendorunit42.paloaltonetworks.comNov 13, 2023, 11:00 AM
  • Google’s Threat Analysis Group Google states that more than 40% of zero-day flaws discovered in 2022 were variants of previous issues. The popular Threat Analysis Group (TAG) Maddie Stone wrote Google’s fourth annual year-in-review of zero-day flaws exploited in-the-wild [2021, 2020, 2019], it is built off of the mid-year 2022 review. In 2022, the researchers […]

    newssecurityaffairs.comJul 30, 2023, 4:38 PM
  • Google Project Zero states that in H1 2022 at least half of zero-day issues exploited in attacks were related to not properly fixed old flaws. Google Project Zero researcher Maddie Stone published a blog post that resumes her speech at the FIRST conference in June 2022, the presentation is titled “0-day In-the-Wild Exploitation in 2022…so […]

    newssecurityaffairs.comJul 3, 2022, 1:31 PM
  • Google Project Zero has observed a total of 18 exploited zero-day vulnerabilities in the first half of 2022, at least half of which exist because previous bugs were not properly addressed.

    newswww.securityweek.comJul 1, 2022, 11:12 AM
  • Attackers are leveraging Follina. What can you do?Help Net Security

    As the world is waiting for Microsoft to push out a patch for CVE-2022-30190, aka “Follina”, attackers around the world are exploiting the vulnerability in a variety of campaigns. A complex vulnerability Microsoft has described CVE-2022-30190 as a Microsoft Windows Support Diagnostic Tool (MSDT) remote code execution vulnerability, confirmed it affects an overwheming majority of Windows and Windows Server versions, and advised on a workaround to be implemented until a patch is ready. Vulnerability analysts … More →

    newswww.helpnetsecurity.comJun 3, 2022, 4:08 PM
  • A newly numbered Windows zero-day vulnerability (CVE-2022-30190) is being exploited in the wild via specially crafted Office documents (without macros), security researchers are warning. After initially dismissing the vulnerability as “not a security related issue”, Microsoft has now issued a CVE and has offered a temporary workaround until fixes can be provided. Detected attacks Boobytrapped office files delivered via email are one of the most common tactics attackers use to compromise endpoints, and they are … More →

    newswww.helpnetsecurity.comMay 31, 2022, 9:12 AM
  • 21st March – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 21st March, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Check Point Research has found sensitive data of a number of mobile applications exposed and available to anyone. By searching VirusTotal, CPR found 2113 mobile applications whose databases were unprotected and exposed […]

    vendorresearch.checkpoint.comMar 21, 2022, 1:48 PM
  • Google’s Threat Analysis Group (TAG) uncovered a new initial access broker, named Exotic Lily, that is closely affiliated with the Conti ransomware gang. Google’s Threat Analysis Group (TAG) researchers linked a new initial access broker, named Exotic Lily, to the Conti ransomware operation. Initial access brokers play an essential role in the cybercrime ecosystem, they provide access to previously […]

    newssecurityaffairs.comMar 19, 2022, 1:15 PM
  • Google on Thursday published an analysis of the activities associated with an initial access broker (IAB) linked to a Russian-speaking cybercrime group tracked as FIN12 and Wizard Spider.

    newswww.securityweek.comMar 18, 2022, 3:09 PM
  • wards of 5,000 emails a day across 650 global organisations, attempting to exploit a Microsoft zero-day vulnerability ( CVE-2021-40444 ) to achieve initial access. Uniquely personal approach Google’s TAG said EXOTIC LILY displayed targeted attack techniques such as spoofing companies and employees as a means to gaining trust through email campaigns but

    newswww.itpro.comMar 18, 2022, 11:58 AM
  • The TTPs of Conti’s initial access brokerHelp Net Security

    Automation might be the way to go for many things, but a recently published report by Google’s Threat Analysis Group (TAG) shows why targeted phishing campaigns performed by human operators are often successful, and how the Conti ransomware gang excels at targeting organizations with the help of an initial access broker. Exotic Lily: A threat actor specializing in gaining initial access into organizations TAG researchers Vlad Stolyarov and Benoit Sevens have delineated the tactics, techniques … More →

    newswww.helpnetsecurity.comMar 18, 2022, 11:16 AM
  • The Google Threat Analysis Group (TAG) has shared their observations about a group of cybercriminals called Exotic Lily. This group has…

    newswww.malwarebytes.comMar 17, 2022, 5:00 PM
  • High-ranking government officials and individuals in the defense industry in Western Asia were targeted in a sophisticated campaign that involved the use of Graphite malware, according to XDR firm Trellix , which resulted from the merger between McAfee Enterprise and FireEye.

    newswww.securityweek.comJan 26, 2022, 6:26 PM
  • Security Affairs newsletter Round 346Security Affairs

    A new round of the weekly Security Affairs newsletter arrived! Every week the best security articles from Security Affairs free for you in your email box. If you want to also receive for free the newsletter with the international press subscribe here. New Rook Ransomware borrows code from Babuk Omicron-themed phishing attacks spread Dridex and taunt […]

    newssecurityaffairs.comDec 26, 2021, 2:17 PM
  • Here’s an overview of some of last week’s most interesting news, articles and interviews: The Log4j saga: New vulnerabilities and attack vectors discovered The Apache Log4j saga continues, as several new vulnerabilities have been discovered in the popular library since Log4Shell (CVE-2021-44228) was fixed by releasing Log4j v2.15.0. Log4Shell is a dumpster fire that should have been avoided If basic IT hygiene guidance had been followed, Log4j would have easily been immune to this type … More →

    newswww.helpnetsecurity.comDec 26, 2021, 9:00 AM
  • Crooks discovered how to bypass the patch for a recent Microsoft Office vulnerability (CVE-2021-40444) and are using it to distribute Formbook malware. Cybercriminals have found a way to bypass the patch for a recent Microsoft Office vulnerability tracked as CVE-2021-40444 (CVSS score of 8.8). The bad news is that threat actors are using it to […]

    newssecurityaffairs.comDec 23, 2021, 2:49 PM
  • Cybercriminals have found a way to bypass the patch for a recent Microsoft Office vulnerability and leveraged it to briefly distribute Formbook malware, Sophos reports.

    newswww.securityweek.comDec 23, 2021, 12:22 PM
  • Sophos Labs researchers have detected the use of a novel exploit able to bypass a patch for a critical vulnerability (CVE-2021-40444) affecting the Microsoft Office file format. The attackers took a publicly available proof-of-concept Office exploit and weaponized it to deliver Formbook malware. The attackers then distributed it through spam emails for approximately 36 hours before it disappeared. From CAB to “CAB-less” exploit to bypass the patch for CVE-2021-40444 The CVE-2021-40444 vulnerability is a critical … More →

    newswww.helpnetsecurity.comDec 22, 2021, 9:19 AM
  • Microsoft software products are a connective tissue of many organizations, from online documents (creating, sharing, storing), to email and calendaring, to the operating systems that enable business operations on the front and back ends, both in the cloud and on premises. Over 1 million companies worldwide and over 731,000 companies in the U.S. use Office 365, and though Microsoft offers no hard stats, some sources suggest there are over 90,000 Microsoft partners facilitating services and … More →

    newswww.helpnetsecurity.comDec 10, 2021, 6:30 AM
  • 29th November – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 29th November, please download our Threat Intelligence Bulletin. Top Attacks and Breaches GoDaddy has announced they suffered a data breach with data of up to 1.2 million of its customers being exposed after an unauthorized person used a compromised password to gain access to […]

    vendorresearch.checkpoint.comNov 29, 2021, 3:46 PM
  • An Iranian threat actor is stealing Google and Instagram credentials of Farsi-speaking targets by exploiting a Microsoft MSHTML bug. Researchers from SafeBreach Labs have identified a new Iranian threat actor that is exploiting a Microsoft MSHTML Remote Code Execution (RCE) vulnerability in attacks targeting Farsi-speaking victims. The exploit is used to install a PowerShell stealer, […]

    newssecurityaffairs.comNov 25, 2021, 12:32 PM
  • 15th November – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 15th November, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Check Point Research notes a 178% increase in the number of malicious shopping websites, compared to the rest of the year, spotting over 5300 different malicious websites per week ahead of the […]

    vendorresearch.checkpoint.comNov 15, 2021, 2:13 PM
  • HP recently released the latest edition of the HP Wolf Security Threat Insights Report. The report reviews notable malware isolated by HP Wolf Security in the third quarter of 2021 so that security teams can better understand the threat landscape and defend their environments. Highlights from this report include an analysis of how HP Sure Click‘s process isolation […]

    newswww.csoonline.comOct 29, 2021, 9:53 PM
  • So far, 2021 has proved to be somewhat of a security annus horribilis for tech giant Microsoft, with numerous vulnerabilities impacting several of its leading services, including Active Directory, Exchange, and Azure. Microsoft is no stranger to being targeted by attackers seeking to exploit known and zero-day vulnerabilities, but the rate and scale of the […]

    newswww.csoonline.comOct 18, 2021, 9:00 AM
  • The US Cybersecurity and Infrastructure Security Agency (CISA) has designated October as Cybersecurity Awareness Month. In honor of this event, I urge you to take the month of October to become more aware of your computer and network assets. Inventory and evaluate software for risks One way to become more aware of your cybersecurity risks […]

    newswww.csoonline.comOct 13, 2021, 9:00 AM
  • The latest report from the WatchGuard shows an astonishing 91.5% of malware arriving over encrypted connections during Q2 2021. This is a dramatic increase over the previous quarter and means that any organization that isn’t examining encrypted HTTPS traffic at the perimeter is missing 9/10 of all malware. Researchers also found alarming surges across fileless malware threats, a dramatic growth in ransomware and a big increase in network attacks. “With much of the world still … More →

    newswww.helpnetsecurity.comOct 6, 2021, 4:30 AM
  • A cyberespionage campaign hit multiple Russian organizations, including JSC GREC Makeyev, a major defense contractor, exploiting a recently disclosed zero-day. Security researchers from Malwarebytes uncovered multiple attacks targeting many Russian organizations, including JSC GREC Makeyev, a company that develops liquid and solid fuel for Russia’s ballistic missiles and space rocket program. Threat actors behind the cyberespionage […]

    newssecurityaffairs.comSep 26, 2021, 11:23 AM
  • Threat actors have targeted Russian government organizations with malicious documents designed to exploit the recently patched MSHTML zero-day flaw in Microsoft Office, security researchers with Malwarebytes reveal.

    newswww.securityweek.comSep 23, 2021, 11:35 AM
  • Once again attackers have used Office files in targeted attacks against Microsoft users. This time they used the Windows Explorer preview pane to deliver malicious .doc, .docm, and .docx files. Researchers have found that malicious .rtf files can also be used in such attacks. For this exploit, an attacker crafts a malicious ActiveX control to […]

    newswww.csoonline.comSep 22, 2021, 9:00 AM
  • Malwarebytes has reason to believe that the MSHTML vulnerability listed under CVE-2021-40444 is being used to target Russian entities. The Malwarebytes…

    newswww.malwarebytes.comSep 21, 2021, 5:00 PM
  • 20th September – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 20th September, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Check Point Research has seen a global surge in the black market for fake COVID-19 vaccine certificates on Telegram, following US President Biden’s vaccine mandate announcements. The black market has expanded to […]

    vendorresearch.checkpoint.comSep 19, 2021, 3:08 PM
  • Security Affairs newsletter Round 332Security Affairs

    A new round of the weekly Security Affairs newsletter arrived! Every week the best security articles from Security Affairs free for you in your email box. The Biden administration plans to target exchanges supporting ransomware operations with sanctions Threat actor has been targeting the aviation industry since at least 2018 Expert discloses details and PoC […]

    newssecurityaffairs.comSep 19, 2021, 8:14 AM
  • Here’s an overview of some of last week’s most interesting news, articles and interviews: Apple fixes “zero-click” iMessage zero-day exploited to deliver spyware (CVE-2021-30860) Apple has released security updates for macOS, iOS, iPadOS, watchOS and Safari that patch two vulnerabilities (CVE-2021-30860, CVE-2021-30858) that are being exploited in attacks in the wild. Kali Linux 2021.3 released: Kali NetHunter on a smartwatch, wider OpenSSL compatibility, new tools, and more! Offensive Security has released Kali Linux 2021.3, the … More →

    newswww.helpnetsecurity.comSep 19, 2021, 8:00 AM
  • Microsoft revealed that multiple threat actors are exploiting the recently patched Windows MSHTML remote code execution security flaw (CVE-2021-40444). Microsoft warns of multiple threat actors, including ransomware operators, that are exploiting the recently patched Windows MSHTML remote code execution security flaw (CVE-2021-40444) in attacks against organizations. The IT giant says that threat actors started targeting […]

    newssecurityaffairs.comSep 16, 2021, 5:23 PM
  • The recent targeted attacks exploiting the (at the time) zero-day remote code execution vulnerability (CVE-2021-40444) in Windows via booby-trapped Office documents have been delivering custom Cobalt Strike payloads, Microsoft and Microsoft-owned RiskIQ have shared. The researchers also found connections between the attackers’ exploit delivery infrastructure and an infrastructure previously used by attackers to deliver human-operated ransomware, the Trickbot trojan and the BazaLoader backdoor/downloader. The attacks and their possible goals Judging by the email lures used … More →

    newswww.helpnetsecurity.comSep 16, 2021, 2:45 PM
  • Microsoft and threat intelligence company RiskIQ reported finding links between the exploitation of a recently patched Windows zero-day vulnerability and known ransomware operators.

    newswww.securityweek.comSep 16, 2021, 10:51 AM
  • Microsoft Patch Tuesday security updates for September 2021 addressed a high severity zero-day flaw actively exploited in targeted attacks. Microsoft Patch Tuesday security updates for September 2021 addressed a high severity zero-day RCE actively exploited in targeted attacks aimed at Microsoft Office and Office 365 on Windows 10 computers. The flaw, tracked as CVE-2021-40444, resides in the MSHTML, […]

    newssecurityaffairs.comSep 15, 2021, 5:03 AM
  • On September 2021 Patch Tuesday, Microsoft has fixed 66 CVE-numbered vulnerabilities in a wide variety of its solutions. Of these, the most crucial to address is CVE-2021-40444, the remote code execution MSHTML vulnerability actively exploited by attackers via malicious MS Office documents. “After this bug was discovered and became public knowledge on September 7, security researchers and analysts began swapping proof-of-concept examples of how an attacker might leverage the exploit,” noted SophosLabs Principal Researcher Andrew … More →

    newswww.helpnetsecurity.comSep 14, 2021, 6:47 PM
  • Microsoft on Tuesday shipped a major security update to blunt zero-day attacks targeting a gaping hole in its proprietary MSHTML browsing engine.

    newswww.securityweek.comSep 14, 2021, 6:32 PM
  • 13th September – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 13th September, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Mēris, a new distributed denial-of-service (DDos) botnet has broken a record with a 21.8 million requests-per-second attack on Russian internet company Yandex; 250,000 devices are assumed to be compromised. MyRepublic, a Singaporean […]

    vendorresearch.checkpoint.comSep 13, 2021, 2:14 PM
  • Here’s an overview of some of last week’s most interesting news, articles and interviews: Attackers are exploiting zero-day RCE flaw to target Windows users (CVE-2021-40444) Attackers are exploiting CVE-2021-40444, a zero-day remote code execution vulnerability in MSHTML (the main HTML component of the Internet Explorer browser), to compromise Windows/Office users in “a limited number of targeted attacks,” Microsoft has warned. September 2021 Patch Tuesday forecast: It’s new operating system season Microsoft has released Server 2022 … More →

    newswww.helpnetsecurity.comSep 12, 2021, 8:00 AM
  • Summer vacations are coming to a close and, for many, the children are finally going back to school providing some quiet time. I hope everyone is well rested because the fall is already shaping up to be a busy time. Microsoft has released Server 2022 and Windows 11 is coming in October. Apple also has the beta available for the next version of macOS. But let’s start by focusing on a new Office vulnerability before … More →

    newswww.helpnetsecurity.comSep 10, 2021, 5:48 AM
  • Microsoft warns of a zero-day vulnerability in Internet Explorer that is actively exploited by threat actors using weaponized Office docs. Microsoft warns of a zero-day vulnerability (CVE-2021-40444) in Internet Explorer that is actively exploited by threat actors to hijack vulnerable Windows systems. Microsoft did not share info about the attacks either the nature of the […]

    newssecurityaffairs.comSep 8, 2021, 12:07 PM
  • Attackers are exploiting CVE-2021-40444, a zero-day remote code execution vulnerability in MSHTML (the main HTML component of the Internet Explorer browser), to compromise Windows/Office users in “a limited number of targeted attacks,” Microsoft has warned on Tuesday. About CVE-2021-40444 and the attacks CVE-2021-40444 is a set of logical flaws that can be leveraged by remote, unauthenticated attackers to execute code on the target system. The current attacks were detected by Microsoft, Mandiant, and Expmon researchers. … More →

    newswww.helpnetsecurity.comSep 8, 2021, 8:47 AM
  • Microsoft’s embattled security response unit is scrambling to deal with another zero-day attack hitting users of its flagship Microsoft Office software suite.

    newswww.securityweek.comSep 7, 2021, 8:00 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

1 repository references · best confidence 0.99 · max 832 stars

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence