Executive brief
The Microsoft Windows Scripting Engine contains a memory corruption vulnerability caused by an out-of-bounds write (CWE-787). An attacker could exploit this by convincing a user to visit a specially crafted website or open a malicious file, potentially leading to remote code execution.
Affected products
- Microsoft Windows 10 up to (excluding) 10.0.10240.19003
- Microsoft Windows 10 Version 1607 up to (excluding) 10.0.14393.4530
- Microsoft Windows 10 Version 1809 up to (excluding) 10.0.17763.2061
- Microsoft Windows 10 Version 1909 up to (excluding) 10.0.18363.1679
- Microsoft Windows 10 Version 2004 up to (excluding) 10.0.19041.1110
- Microsoft Windows 10 Version 20H2 up to (excluding) 10.0.19042.1110
- Microsoft Windows 10 Version 21H1 up to (excluding) 10.0.19043.1110
- Microsoft Windows 7 Service Pack 1
- Microsoft Windows 8.1
- Microsoft Windows RT 8.1
- Microsoft Windows Server 2008 R2 Service Pack 1
- Microsoft Windows Server 2012
- Microsoft Windows Server 2012 R2
- Microsoft Windows Server 2016 up to (excluding) 10.0.14393.4530
- Microsoft Windows Server 2019 up to (excluding) 10.0.17763.2061
Timeline
- 2021-07-13: disclosed: MSRC Advisory Published
- 2021-07-22: patched: Initial NIST analysis and patch reference added
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: exploited: Confirmed exploited in the wild per CISA KEV catalog and advisory report.