LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-40444: Microsoft MSHTML Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Nov 17, 2021
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-40444 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of Nov 17, 2021 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Microsoft MSHTML contains a unspecified vulnerability that allows for remote code execution.

CVE-2021-40444 is a remote code execution vulnerability in Microsoft MSHTML, the component Windows uses to render web content in applications such as Office and the browser engine. CISA describes it as an unspecified flaw that allows remote code execution. It matters because successful abuse can let an attacker run code on a user’s system, and this CVE has been associated with known ransomware use. Defenders should treat it as a high-priority patch item and confirm all version and configuration details against the vendor advisory.

How it works

The weakness is classified as CWE-22 (improper limitation of a pathname to a restricted directory, often called path traversal). In products that embed MSHTML, this class of flaw can allow crafted input to influence how the component resolves or loads resources, ultimately leading to remote code execution when a user opens or previews malicious content. Public detail on the exact trigger and exploit mechanics is limited in the provided record; treat the attack surface as document- or content-driven abuse of the MSHTML rendering path. An attacker typically needs to deliver a specially crafted file or content that the victim opens in an application that invokes MSHTML. Do not rely on incomplete public write-ups—confirm behavior and affected configurations against Microsoft’s advisory.

Am I affected? How to find it in your systems

MSHTML is part of the Windows platform and is used by Microsoft Office and other applications that render HTML or related content. It typically appears on Windows endpoints and servers where Office or browser-related components are installed.

How to remediate

Patch first. CISA’s required action is to apply updates per vendor instructions. Deploy the Microsoft security updates that address CVE-2021-40444 across all affected Windows and Office environments as soon as your change process allows, and verify installation with your patch-management reporting.

If you can't patch immediately

If you cannot complete patching at once, reduce exposure with compensating controls until updates are installed.

If your data may have been exposed

Actively exploited vulnerabilities, including those with known ransomware use, can lead to account takeover, malware installation, and data theft. If you suspect compromise, isolate affected hosts, preserve logs, and follow your incident-response process, including credential resets and ransomware containment steps as appropriate. You can run a free exposure scan of your email addresses against known breach data to see whether associated credentials or personal data have appeared in prior breaches, then prioritize password changes and monitoring for any matches.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · MSHTML
WeaknessCWE-22
Added to CISA KEVNov 3, 2021
Federal patch deadlineNov 17, 2021
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities