# Microsoft MSHTML Zero-Day CVE-2021-40444 Exploited

Published: 2021-09-14 · Severity: critical
Canonical: https://vorant.io/reports/f717fd36-0885-5c87-b4a0-bafdae263079/microsoft-mshtml-zero-day-cve-2021-40444-exploited

> A actively exploited MSHTML remote code execution flaw in Windows was patched by Microsoft in its September 2021 update; IPA urges immediate patching.

IPA (Japan's Information-technology Promotion Agency) issued an alert on CVE-2021-40444, a remote code execution vulnerability in Microsoft MSHTML affecting multiple Windows products. Microsoft confirmed active exploitation in the wild at the time of disclosure, raising concern that attacks could spread further before organizations apply defenses.

Microsoft released workarounds and mitigations at initial disclosure, followed by an official patch in the September 2021 Patch Tuesday cycle. IPA's advisory was updated on September 15, 2021 to reflect the release of the fix and to urge affected organizations to apply the patch immediately via Windows Update rather than relying solely on interim mitigations.

The vulnerability allows an attacker to achieve arbitrary code execution, which could lead to a range of downstream impacts depending on attacker objectives. Given the confirmed in-the-wild exploitation prior to patch availability, this represents a genuine zero-day threat to widely deployed Windows systems, though the advisory itself does not name specific threat actors, malware, or targeted sectors.

## Mentioned in this report

- Vulnerabilities: CVE-2021-40444 (KEV)

Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2021/20210908-ms.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/f717fd36-0885-5c87-b4a0-bafdae263079/microsoft-mshtml-zero-day-cve-2021-40444-exploited.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
