Executive brief
Microsoft Windows MSHTML Platform contains an out-of-bounds write vulnerability (CWE-787) that allows for remote code execution. The vulnerability is triggered when a user visits a specially crafted website or opens a malicious file, leading to memory corruption.
Affected products
- Microsoft Windows 10 1507, 1607, 1809, 1909, 2004, 20H2, 21H1
- Microsoft Windows 7 SP1
- Microsoft Windows 8.1
- Microsoft Windows RT 8.1
- Microsoft Windows Server 2008 R2 SP1, SP2
- Microsoft Windows Server 2012 R2
- Microsoft Windows Server 2016 2004, 20H2, 1909
- Microsoft Windows Server 2019
Timeline
- 2021-06-14: disclosed: Initial analysis by NIST
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: advisory: Published date listed in advisory
- 2021-11-03: exploited: Reported as exploited in the wild in CISA KEV catalog