# Microsoft patched CVE-2021-40444, an MSHTML vulnerability in Windows actively exploited…

Published: 2021-09-14 · Severity: critical
Canonical: https://vorant.io/reports/46090d4c-d647-450a-b58e-6c4950557ecc/microsoft-patched-cve-2021-40444-an-mshtml-vulnerability-in-windows-actively

> Microsoft patched CVE-2021-40444, an MSHTML vulnerability in Windows actively exploited in the wild, enabling remote code execution via malicious Office documents.

On September 8, 2021, Microsoft disclosed CVE-2021-40444, a remote code execution vulnerability in the MSHTML rendering engine affecting multiple Windows versions. The vulnerability allows attackers to execute arbitrary code when a user opens a specially crafted Microsoft Office document containing a malicious ActiveX control. Microsoft confirmed active exploitation in the wild at the time of disclosure.

The Japan Information-technology Promotion Agency (IPA) issued this alert urging immediate application of Microsoft's September 2021 security updates. Prior to patch availability, Microsoft provided workarounds including disabling the installation of all ActiveX controls in Internet Explorer and implementing attack surface reduction rules in Microsoft Defender.

Given confirmed in-the-wild exploitation and the ease of delivery via Office documents, organizations should treat this as a critical patching priority. The vulnerability affects Windows Server 2008 through 2019, Windows 7 through 11, and various Windows 10 versions, making the attack surface substantial across enterprise environments.

## Mentioned in this report

- Vulnerabilities: CVE-2021-40444 (KEV)

Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2021/20210908-ms.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/46090d4c-d647-450a-b58e-6c4950557ecc/microsoft-patched-cve-2021-40444-an-mshtml-vulnerability-in-windows-actively.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
