CVE-2021-40444General(microsoft / windows_10_1507)

CRITICALCVSS 7.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch microsoft windows_10_1507 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using specially-crafted Microsoft Office documents. An attacker could craft a malicious ActiveX control to be used by a Microsoft Office document that hosts the browser rendering engine. The attacker would then have to convince the user to open the malicious document. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Microsoft Defender Antivirus and Microsoft Defender for Endpoint both provide detection and protections for the known vulnerability. Customers should keep antimalware products up to date. Customers who utilize automatic updates do not need to take additional action. Enterprise customers who manage updates should select the detection build 1.349.22.0 or newer and deploy it across their environments. Microsoft Defender for Endpoint alerts will be displayed as: “Suspicious Cpl File Execution”. Upon completion of this investigation, Microsoft will take the appropriate action to help protect our customers. This may include providing a security update through our monthly release process or providing an out-of-cycle security update, depending on customer needs. Please see the Mitigations and Workaround sections for important information about steps you can take to protect your system from this vulnerability. UPDATE September 14, 2021: Microsoft has released security updates to address this vulnerability. Please see the Security Updates table for the applicable update for your system. We recommend that you install these updates immediately. Please see the FAQ for important information about which updates are applicable to your system.

8.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2021-11-17. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-22

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1507
  • windows_10_1607
  • windows_10_1809
  • windows_10_1909

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 5 mentions across 4 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • General: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-06-24)
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
windows_10_1507windows_10_1607windows_10_1809windows_10_1909windows_10_2004windows_10_20h2windows_10_21h1windows_7windows_8.1windows_rt_8.1

2 versions affected across 17 products

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-01-28: 1Mentions · 2026-03-07: 1Mentions · 2026-05-15: 1Mentions · 2026-06-24: 2PoC Mentioned / Linked · 2026-01-28: 1Exploit Tool / Code · 2026-06-24: 1Active Exploitation · 2026-06-24: 1Patch / Workaround · 2026-06-24: 1Technical Details · 2026-01-28: 1Technical Details · 2026-03-07: 1Technical Details · 2026-06-24: 201-2803-0705-1506-24
Signal classification3 categories
General
360.0%
PoC
120.0%
Active Exploitation
120.0%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-01-281
PoC1
2026-03-071
General1
2026-05-151
General1
2026-06-242
Active Exploitation1General1
Full discourse5 posts
  • OS Dev@OSdev_
    General

    CVE-2021-40444 was a reminder that attackers don't always need macros. A malicious Word document could leverage the legacy MSHTML (Internet Explorer) engine to load attacker-controlled content and trigger code execution through ActiveX. It's a fascinating case study in how decades of Windows compatibility layers, Office, OLE, COM, ActiveX, and MSHTML, can combine into a powerful attack chain.

    Post summary

    The passage highlights how legacy Windows components can be abused in CVE-2021-40444, but provides no evidence of active exploits, patches, or PoC code.

    118284297.6K
    4.8K followersView on X
  • Philippe Lagadec@decalage2
    PoC

    So to exploit CVE-2026-21509 from MS Office files, one could use either an OLE object of type "Shell.Explorer", or an external relationship with a special URL that would trigger the use of the Internet Explorer engine, as it was the case for CVE-2021-40444 with "mhtml:" URLs.

    Post summary

    The post outlines a potential exploitation technique for CVE‑2026‑21509 by using a Shell.Explorer OLE object or a specially crafted URL that triggers the Internet Explorer engine in Office files.

    120601.0K
    5.3K followersView on X
  • OS Dev@OSdev_
    Active Exploitation

    https://www.fortinet.com/blog/threat-research/merkspy-exploiting-cve-2021-40444-to-infiltrate-systems

    Post summary

    The blog explains how the MerkSpy threat group actively exploited CVE-2021-40444 to infiltrate systems, detailing the exploit method and noting available remediation.

    00043546
    4.8K followersView on X
  • truemorgan@_truemorgan
    General

    Windows: CVE-2017-0144 CVE-2017-0145 CVE-2008-4250 CVE-2019-0708 CVE-2020-1472 CVE-2021-34527 CVE-2021-26855 CVE-2020-1350 CVE-2003-0352 CVE-2014-6324 CVE-2017-0199 CVE-2021-40444 CVE-2022-30190 CVE-2021-31166 CVE-2022-21907 CVE-2019-1182 CVE-2019-1181 CVE-2020-0601 CVE-2023-29363 CVE-2023-32014 CVE-2025-24985 CVE-2025-24993 CVE-2024-38063 CVE-2022-34718 CVE-2021-26857 CVE-2021-36934 CVE-2022-37969 CVE-2022-41033 CVE-2022-38028 CVE-2023-28252 CVE-2024-26169 CVE-2025-29824 CVE-2025-30400 CVE-2025-32701 CVE-2025-32706 CVE-2016-0099 CVE-2020-1048 CVE-2017-8529 CVE-2020-0688 CVE-2021-42287 CVE-2021-42278 CVE-2022-26923 CVE-2021-34523 CVE-2021-31207 CVE-2026-32202 CVE-2017-5754 CVE-2017-5753 CVE-2018-3639 CVE-2019-11135 CVE-2018-3620

    Post summary

    The text simply lists Windows CVE identifiers without any additional context, evidence of exploitation, or remediation information.

    10000106
    15 followersView on X
  • David@davidsheyi
    General

    3/ CVE-2021-40444 was a notable zero-day in MS Office. It highlighted how attackers use document files to execute malicious code. #CVE #Security

    Post summary

    CVE-2021-40444 is a notable MS Office zero‑day that enables attackers to execute malicious code through document files, but the post provides no exploit code, active exploitation evidence, or patch information.

    1000027
    556 followersView on X
CPE platform detail19 entries

19 of 19 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1507---
OSmicrosoftwindows_10_1607---
OSmicrosoftwindows_10_1809---
OSmicrosoftwindows_10_1909---
OSmicrosoftwindows_10_2004---
OSmicrosoftwindows_10_20h2---
OSmicrosoftwindows_10_21h1---
OSmicrosoftwindows_7---
OSmicrosoftwindows_8.1---
OSmicrosoftwindows_rt_8.1---
OSmicrosoftwindows_server_2004---
OSmicrosoftwindows_server_2008---
OSmicrosoftwindows_server_2008r2-x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_20h2---

Explore more