Executive brief
A remote code execution vulnerability exists in the Microsoft MSHTML browser engine when processing specially crafted Microsoft Office documents. An attacker can exploit this by tricking a user into opening a malicious document containing a crafted ActiveX control, potentially leading to full system compromise depending on user permissions.
Affected products
- Microsoft Windows 10 20H2, 21H1, 1607, 1809, 1909, 2004
- Microsoft Windows 7 SP1
- Microsoft Windows 8.1
- Microsoft Windows RT 8.1
- Microsoft Windows Server 2008 SP2, R2 SP1
- Microsoft MSHTML
Timeline
- 2021-09-14: patched: Microsoft released security updates to address the vulnerability.
- 2021-11-03: disclosed: Initial publication date.
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- exploited: Microsoft reported awareness of targeted attacks using specially-crafted Office documents.