VORANT. Threat Intelligence Sign in Get the full feed

Microsoft MSHTML Zero-Day CVE-2021-40444 Exploited

critical vulnerability

A actively exploited MSHTML remote code execution flaw in Windows was patched by Microsoft in its September 2021 update; IPA urges immediate patching.

IPA (Japan's Information-technology Promotion Agency) issued an alert on CVE-2021-40444, a remote code execution vulnerability in Microsoft MSHTML affecting multiple Windows products. Microsoft confirmed active exploitation in the wild at the time of disclosure, raising concern that attacks could spread further before organizations apply defenses.

Microsoft released workarounds and mitigations at initial disclosure, followed by an official patch in the September 2021 Patch Tuesday cycle. IPA's advisory was updated on September 15, 2021 to reflect the release of the fix and to urge affected organizations to apply the patch immediately via Windows Update rather than relying solely on interim mitigations.

The vulnerability allows an attacker to achieve arbitrary code execution, which could lead to a range of downstream impacts depending on attacker objectives. Given the confirmed in-the-wild exploitation prior to patch availability, this represents a genuine zero-day threat to widely deployed Windows systems, though the advisory itself does not name specific threat actors, malware, or targeted sectors.

Mentioned in this report

Vulnerabilities CVE-2021-40444KEV

Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2021/20210908-ms.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free