LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-33742: Microsoft Windows MSHTML Platform Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Nov 17, 2021
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-33742 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of Nov 17, 2021 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for remote code execution.

CVE-2021-33742 is a remote code execution vulnerability in the Microsoft Windows MSHTML Platform. An attacker who successfully abuses it can run code in the context of the affected user or process on a Windows system. Because MSHTML is widely used for rendering web content and related document handling across Windows, the issue matters to any organization that runs supported or legacy Windows endpoints and servers. Public detail on exact mechanics is limited; treat the vendor advisory as the source of truth for scope and fixes.

CISA describes the flaw as an unspecified vulnerability in the MSHTML Platform that allows remote code execution and directs defenders to apply updates per Microsoft’s instructions. Known ransomware use is not documented for this CVE.

How it works

The vulnerability is associated with CWE-787 (out-of-bounds write) and CWE-823 (use of out-of-range pointer offset). In this class of weakness, the component mishandles memory or pointer arithmetic when processing crafted input. An attacker supplies malformed content that the MSHTML Platform parses; the out-of-bounds write or bad pointer offset can corrupt memory in a way that leads to arbitrary code execution.

Remote code execution in this product class typically means the attacker needs a way to get the victim’s system to process attacker-controlled content—commonly through a document, web content, or other input that invokes MSHTML. Exact exploit preconditions, required user interaction, and reliable exploitation paths are not specified in the provided facts. Do not assume weaponization details; confirm attack surface and any published exploitation notes against the vendor advisory and your own threat intelligence.

Am I affected? How to find it in your systems

MSHTML is a core Windows component used for HTML rendering and related functionality. It is present on typical Windows client and server installations rather than as a separate optional product. Inventory should focus on Windows endpoints, VDI images, jump hosts, and any servers that process untrusted documents or web content.

If you cannot map a host to a patched build listed by Microsoft, treat it as potentially affected until verified.

How to remediate

Patch first. Apply the Microsoft updates that remediate CVE-2021-33742 exactly as described in the vendor advisory and CISA’s required action: follow vendor instructions for deployment. Use your standard patch pipeline (WSUS, ConfigMgr, Intune, or equivalent), prioritize internet-facing and high-risk user populations, and verify installation via build/KB inventory, not just “update succeeded” messages.

If you can't patch immediately

Compensating controls reduce but do not eliminate risk until the vendor fix is installed.

If your data may have been exposed

Actively exploited remote code execution flaws can lead to endpoint compromise, credential theft, and follow-on data access. Known ransomware use is not documented for this CVE, but any confirmed intrusion should be handled through your incident response process: isolate hosts, preserve evidence, reset credentials, and assess what data the compromised identity could reach. If you want a quick external check on whether your email addresses appear in known breach corpora, you can run a free exposure scan of your email against published breach data and then prioritize password resets and MFA where hits appear.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-787
Added to CISA KEVNov 3, 2021
Federal patch deadlineNov 17, 2021
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities