Microsoft MSHTML Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using specially-crafted Microsoft Office documents. An attacker could craft a malicious ActiveX control to be used by a Microsoft Office document that hosts the browser rendering engine. The attacker would then have to convince the user to open the malicious document. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Microsoft Defender Antivirus and Microsoft Defender for Endpoint both provide detection and protections for the known vulnerability. Customers should keep antimalware products up to date. Customers who utilize automatic updates do not need to take additional action. Enterprise customers who manage updates should select the detection build 1.349.22.0 or newer and deploy it across their environments. Microsoft Defender for Endpoint alerts will be displayed as: “Suspicious Cpl File Execution”. Upon completion of this investigation, Microsoft will take the appropriate action to help protect our customers. This may include providing a security update through our monthly release process or providing an out-of-cycle security update, depending on customer needs. Please see the Mitigations and Workaround sections for important information about steps you can take to protect your system from this vulnerability. UPDATE September 14, 2021: Microsoft has released security updates to address this vulnerability. Please see the Security Updates table for the applicable update for your system. We recommend that you install these updates immediately. Please see the FAQ for important information about which updates are applicable to your system.
🎯 Affected products41
- Windows 10 Version 1607 for 32-bit Systems
- Windows 10 Version 1607 for x64-based Systems
- Windows 10 Version 1809 for 32-bit Systems
- Windows 10 Version 1809 for ARM64-based Systems
- Windows 10 Version 1809 for x64-based Systems
- Windows 10 Version 1909 for 32-bit Systems
- Windows 10 Version 1909 for ARM64-based Systems
- Windows 10 Version 1909 for x64-based Systems
- Windows 10 Version 2004 for 32-bit Systems
- Windows 10 Version 2004 for ARM64-based Systems
- Windows 10 Version 2004 for x64-based Systems
- Windows 10 Version 20H2 for 32-bit Systems
- Windows 10 Version 20H2 for ARM64-based Systems
- Windows 10 Version 21H1 for 32-bit Systems
- Windows 10 Version 21H1 for ARM64-based Systems
- Windows 10 Version 21H1 for x64-based Systems
- Windows 10 for 32-bit Systems
- Windows 10 for x64-based Systems
- Windows 7 for 32-bit Systems Service Pack 1
- Windows 7 for x64-based Systems Service Pack 1
- Windows 8.1 for 32-bit systems
- Windows 8.1 for x64-based systems
- Windows RT 8.1
- Windows Server 2008 R2 for x64-based Systems Service Pack 1
- Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
- Windows Server 2008 for 32-bit Systems Service Pack 2
- Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
- Windows Server 2008 for x64-based Systems Service Pack 2
- Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
- Windows Server 2012
- +11 more not shown
✅ Remediation
KB5005568 (Security Update) — fixed build 10.0.17763.2183 KB5005566 (Security Update) — fixed build 10.0.18363.1801 KB5005565 (Security Update) — fixed build 10.0.19043.1237 KB5005575 (Security Update) — fixed build 10.0.20348.230 KB5005565 (Security Update) — fixed build 10.0.19041.1237 KB5005565 (Security Update) — fixed build 10.0.19042.1237 KB5005569 (Security Update) — fixed build 10.0.10240.19060 KB5005573 (Security Update) — fixed build 10.0.14393.4651 KB5005633 (Monthly Rollup) — fixed build 6.1.7601.25712 KB5005563 (IE Cumulative) — fixed build 1.001 KB5019958 (IE Cumulative) — fixed build 6.1.7601.26221 KB5005613 (Monthly Rollup) — fixed build 6.3.9600.20120 KB5005627 (Security Only) — fixed build 6.3.9600.20120 KB5005606 (Monthly Rollup) — fixed build 6.0.6003.21218 KB5005623 (Monthly Rollup) — fixed build 6.2.9200.23462
🔗 References (27)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40444
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5005568
- referencehttps://support.microsoft.com/help/5005568
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5005566
- referencehttps://support.microsoft.com/help/5005566
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5005565
- referencehttps://support.microsoft.com/help/5005565
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5005575
- referencehttps://support.microsoft.com/help/5005575
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5005569
- referencehttps://support.microsoft.com/help/5005569
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5005573
- referencehttps://support.microsoft.com/help/5005573
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5005633
- referencehttps://support.microsoft.com/help/5005633
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5005563
- referencehttps://support.microsoft.com/help/5005563
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5019958
- referencehttps://support.microsoft.com/help/5019958
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5005613
- referencehttps://support.microsoft.com/help/5005613
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5005627
- referencehttps://support.microsoft.com/help/5005627
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5005606
- referencehttps://support.microsoft.com/help/5005606
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5005623
- referencehttps://support.microsoft.com/help/5005623