Active exploitation of Microsoft vulnerability (CVE-2021-40444)

On September 7, 2021, Microsoft disclosed a remote code execution vulnerability (CVE-2021-40444) in the Internet Explorer MSHTML browser engine (also known as Trident). As of this publication, threat actors are actively exploiting the flaw using specially crafted Microsoft Office documents.

By convincing a user to open a malicious document that exploits this flaw, a threat actor could execute arbitrary code on the system. The impact depends on the user`s access privileges but could include malware running with the same privileges as the user. The vulnerability affects multiple Microsoft Windows versions from Windows 7 to Windows Server 2022.

Our Security Partner analysis of a malicious document that appears to exploit CVE-2021-40444 and deploy Cobalt Strike as a final payload indicates that the exploit could have been used in the wild since at least August 16. Microsoft Defender Antivirus and Microsoft Defender for Endpoint provide protection for this vulnerability as of build 1.349.22.0.

Recommended actions:

Microsoft states that opening Microsoft Office documents in Protected View or using Application Guard for Office prevents this exploit. A patch is not available as of this publication. We recommend that customers review the Microsoft advisory and apply the mitigation and workaround guidance as appropriate in their environments.


If you have any questions or concerns about this advisory, please contact us via our support desk – support@empsn.org.uk



Keeping Up To Date With Us Is Easy, Sign Up To Our Newsletter Today!

Stay in touch with emPSN, so that you get the latest e-safety advice and invites to our community events.

Our partners