Microsoft Finds Remote Code Execution Vulnerability In MSHTML

September 8, 2021

Microsoft has identified a couple of attacks that target a remote code execution vulnerability in MSHTML that affects Microsoft Windows. This also prompted CISA to issue a statement asking “users and organizations to review Microsoft’s mitigations and workarounds to address the remote code execution vulnerability identified as CVE-2021-40444.”

Rick Cole of Microsoft Security Response Center, Haifei Li of EXPMON, Dhanesh Kizhakkinan, Bryce Abdo, and Genwei Jiang of Mandiant discovered the vulnerability.

The Microsoft release mentions that its Defender Antivirus and Defender for Endpoint protect against the vulnerability, so anyone who has the tools and uses automatic updates is safe from the vulnerability. The tech giant also pointed out that enterprise customers who manage updates should “select the detection build 1.349.22.0 or newer and install it across their environments.”

The notifications in Microsoft Defender are displayed as “Suspicious Cpl File Execution.”

Once the investigation is complete, Microsoft will release a security update during Patch Tuesday or in a separate out-of-cycle security update.

In addition, this version adds that Microsoft Office opens documents from the internet in Protected View or Application Guard for Office by default, both of which prevent the attack.

Microsoft recommends disabling the installation of all ActiveX controls in Internet Explorer.

The statement also gave instructions on how to disable ActiveX controls on an individual system.

For more information, read the original story in ZDNet.

Top Stories

Related Articles

April 1, 2026 Anthropic has inadvertently exposed the full source code of its Claude Code tool for the second time more...

April 1, 2026 Cisco suffered a cyberattack after attackers used stolen credentials from a compromised developer tool to access its more...

March 30, 2026 Google has expanded its “Results about you” tool, allowing users to remove highly sensitive personal data, including more...

March 27, 2026 Microsoft is updating GitHub Copilot to train on real-world developer interactions, expanding beyond public code datasets to more...

Picture of TND News Desk

TND News Desk

Staff writer for Tech Newsday.
Picture of TND News Desk

TND News Desk

Staff writer for Tech Newsday.

Jim Love

Jim is an author and podcast host with over 40 years in technology.

Share:
Facebook
Twitter
LinkedIn