Microsoft · Bitdefender Antivirus · CVE-2021-40444
**Name of the Vulnerable Software and Affected Versions**
Microsoft Windows (affected versions not specified)
**Description**
Remote code execution is possible in MSHTML, the browser rendering engine used by Microsoft Internet Explorer and hosted within Microsoft Office documents. The issue stems from incorrect code generation management. An attacker can exploit this by crafting a malicious ActiveX control and embedding it into a Microsoft Office document. If a user is convinced to open the document, the attacker can execute arbitrary code on the system. Users with administrative rights are more severely impacted than those with restricted user rights. Real-world exploitation has been observed in targeted attacks by state-sponsored groups, such as APT 35, and has been used to deploy the MerkSpy spyware to monitor activities and capture sensitive information.
**Recommendations**
Install the security updates released on September 14, 2021, immediately.
For enterprise customers managing updates, deploy Microsoft Defender detection build 1.349.22.0 or newer.
Keep antimalware products up to date to ensure detection and protection.