LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-34448: Microsoft Windows Scripting Engine Memory Corruption Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Nov 17, 2021
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-34448 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of Nov 17, 2021 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Windows Scripting Engine contains an unspecified vulnerability that allows for memory corruption.

CVE-2021-34448 is a memory corruption vulnerability in the Microsoft Windows Scripting Engine. An attacker who successfully abuses it can corrupt memory in a way that may lead to code execution or further compromise on a Windows host. It matters because the scripting engine is widely present on Windows systems and is commonly reached through content that triggers script processing, so unpatched endpoints remain a practical target until vendor updates are applied.

Public detail on exact attack paths is limited; treat this as a memory-corruption issue in a core Windows component and confirm all version, impact, and exploitation specifics against the Microsoft advisory.

How it works

The weakness is classified as CWE-787 (out-of-bounds write). In this class of flaw, the scripting engine mishandles memory such that a write can occur outside the intended buffer bounds. That corruption can alter program state, crash the process, or, under the right conditions, allow an attacker to influence execution flow.

CISA describes the issue only as an unspecified vulnerability that allows memory corruption in the Microsoft Windows Scripting Engine. No further exploit mechanics are provided in the given facts. In general, attackers abuse scripting-engine memory corruption by supplying crafted input that the engine parses or executes, causing the out-of-bounds write. Do not assume a particular vector, privilege level, or reliability of exploitation without checking the vendor advisory.

Am I affected? How to find it in your systems

The affected product is Microsoft Windows. The scripting engine ships as part of the OS and is used by components that process scripts (for example browsers, host applications, or system services that invoke script hosts). Any Windows endpoint or server that has not received the corresponding security update should be treated as potentially vulnerable until verified.

How to remediate

Patch first. Apply the updates Microsoft released for this vulnerability, following the vendor instructions exactly as stated in the advisory. CISA’s required action is to apply updates per vendor instructions.

If you can't patch immediately

Use compensating controls to lower exposure until the vendor update can be installed.

If your data may have been exposed

Actively exploited vulnerabilities can lead to host compromise and follow-on data theft, even when ransomware use is not documented for this CVE. If you suspect exploitation, isolate affected systems, preserve forensic evidence, rotate credentials that may have been present on the host, and follow your incident-response process. You can run a free exposure scan of your email addresses against known breach data to see whether associated accounts appear in prior breaches while you complete containment and recovery.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-787
Added to CISA KEVNov 3, 2021
Federal patch deadlineNov 17, 2021
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities