Vulnerability record · CVE-2021-40444 · published 15 September 2021
CVE-2021-40444: Microsoft MSHTML remote code execution via malicious Office document
Microsoft · Windows 10 1507
CVE-2021-40444 is a remote code execution flaw in the MSHTML browser rendering engine on Microsoft Windows. An attacker can embed a malicious ActiveX control in a crafted Microsoft Office document, and opening that document can execute code in the context of the user. Microsoft confirmed targeted attacks in the wild and released security updates on September 14, 2021.
Description
Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using specially-crafted Microsoft Office documents. An attacker could craft a malicious ActiveX control to be used by a Microsoft Office document that hosts the browser rendering engine. The attacker would then have to convince the user to open the malicious document. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Microsoft Defender Antivirus and Microsoft Defender for Endpoint both provide detection and protections for the known vulnerability. Customers should keep antimalware products up to date. Customers who utilize automatic updates do not need to take additional action. Enterprise customers who manage updates should select the detection build 1.349.22.0 or newer and deploy it across their environments. Microsoft Defender for Endpoint alerts will be displayed as: “Suspicious Cpl File Execution”. Upon completion of this investigation, Microsoft will take the appropriate action to help protect our customers. This may include providing a security update through our monthly release process or providing an out-of-cycle security update, depending on customer needs. Please see the Mitigations and Workaround sections for important information about steps you can take to protect your system from this vulnerability. UPDATE September 14, 2021: Microsoft has released security updates to address this vulnerability. Please see the Security Updates table for the applicable update for your system. We recommend that you install these updates immediately. Please see the FAQ for important information about which updates are applicable to your system.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:L
Automated analysis
critical priorityIt is in CISA KEV with known ransomware use, has a very high EPSS score, public exploits exist, and it enables remote code execution via a common user action.
What it is
CVE-2021-40444 is a remote code execution flaw in the MSHTML browser rendering engine on Microsoft Windows. An attacker can embed a malicious ActiveX control in a crafted Microsoft Office document, and opening that document can execute code in the context of the user. Microsoft confirmed targeted attacks in the wild and released security updates on September 14, 2021.
Impact
Successful exploitation gives the attacker code execution with the privileges of the logged-on user, which can lead to full system compromise if that user has administrative rights. Microsoft notes users with fewer rights are less impacted.
Attack surface
The vector is network-reachable (AV:N) with no privileges required (PR:N) but requires user interaction (UI:R) to open the malicious Office document. No authentication is needed; the attacker must convince the victim to open the file.
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2021-11-03 with a due date of 2021-11-17 and flags known ransomware campaign use. EPSS is 0.9745 (99.897th percentile), and references include public exploit write-ups, indicating active and widespread exploitation.
What to do
- Apply the Microsoft security updates released September 14, 2021 for all affected Windows versions immediately.
- Ensure Microsoft Defender Antivirus and Defender for Endpoint are updated to detection build 1.349.22.0 or newer.
- Disable or restrict ActiveX controls in Office documents and block untrusted Office file execution where feasible.
- Follow Microsoft's published mitigations and workarounds for MSHTML/Office until fully patched.
- Limit user privileges so day-to-day accounts do not run with administrative rights.
Detection
- Monitor for Microsoft Defender for Endpoint alerts named 'Suspicious Cpl File Execution'.
- Hunt for Office processes (WINWORD.EXE, EXCEL.EXE) spawning child processes such as control.exe, rundll32.exe, or other unexpected binaries.
- Look for Office documents loading remote or unusual ActiveX/HTML content, especially from email or downloads.
- Review endpoint telemetry for .cpl or DLL execution originating from Office or temporary directories.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-40444 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Microsoft MSHTML Remote Code Execution Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.
Affected products
17 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40444 | PatchVendor Advisory |
| http://packetstormsecurity.com/files/164210/Microsoft-Windows-MSHTML-Overview.html | Third Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/165214/Microsoft-Office-Word-MSHTML-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/167317/Microsoft-Office-MSDT-Follina-Proof-Of-Concept.html | ExploitThird Party AdvisoryVDB Entry |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-40444 | MitigationPatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-40444 | US Government Resource |
Track CVE-2021-40444 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-40444), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.