PT-2021-3925 · Microsoft · Bitdefender Antivirus+4

·

CVE-2021-40444

·

Published

2021-09-07

·

Updated

2026-08-24

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:N/C:P/I:C/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Windows (affected versions not specified)
Description Remote code execution is possible in MSHTML, the browser rendering engine used by Microsoft Internet Explorer and hosted within Microsoft Office documents. The issue stems from incorrect code generation management. An attacker can exploit this by crafting a malicious ActiveX control and embedding it into a Microsoft Office document. If a user is convinced to open the document, the attacker can execute arbitrary code on the system. Users with administrative rights are more severely impacted than those with restricted user rights. Real-world exploitation has been observed in targeted attacks by state-sponsored groups, such as APT 35, and has been used to deploy the MerkSpy spyware to monitor activities and capture sensitive information.
Recommendations Install the security updates released on September 14, 2021, immediately. For enterprise customers managing updates, deploy Microsoft Defender detection build 1.349.22.0 or newer. Keep antimalware products up to date to ensure detection and protection.

Exploit

Fix

DoS

RCE

Code Injection

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04442
CVE-2021-40444
OPENSUSE-SU-2024:13674-1

Affected Products

Bitdefender Antivirus
Defender For Endpoint
Mshtml
Office
Windows