PT-2021-3925 · Microsoft · Bitdefender Antivirus+4
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:N/C:P/I:C/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows (affected versions not specified)
Description
Remote code execution is possible in MSHTML, the browser rendering engine used by Microsoft Internet Explorer and hosted within Microsoft Office documents. The issue stems from incorrect code generation management. An attacker can exploit this by crafting a malicious ActiveX control and embedding it into a Microsoft Office document. If a user is convinced to open the document, the attacker can execute arbitrary code on the system. Users with administrative rights are more severely impacted than those with restricted user rights. Real-world exploitation has been observed in targeted attacks by state-sponsored groups, such as APT 35, and has been used to deploy the MerkSpy spyware to monitor activities and capture sensitive information.
Recommendations
Install the security updates released on September 14, 2021, immediately.
For enterprise customers managing updates, deploy Microsoft Defender detection build 1.349.22.0 or newer.
Keep antimalware products up to date to ensure detection and protection.
Exploit
Fix
DoS
RCE
Code Injection
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bitdefender Antivirus
Defender For Endpoint
Mshtml
Office
Windows