About CVE-2021-40444
Vulnerability Name | Microsoft MSHTML Remote Code Execution Vulnerability(CVE-2021-40444) |
---|---|
Attack Type | Code Injection |
Time Discovered | 2021-09-07 |
Updated Time | 2022-07-16 |
CVE ID | CVE-2021-40444 |
Summary
The attacker can use this vulnerability to construct a malicious office document and send it to the attacked party, resulting in remote code execution.
Affected Versions
Windows 7 for 32/x64-based Systems Service Pack 1 Windows RT 8.1 Windows 8.1/10 for 32/x64-based Systems Windows 10 Version 1607 for 32/x64-based Systems Windows 10 Version 2004/1809/1909/20H2/21H1 for 32/x64/ARM64-based Systems Windows Server 2012/2012 R2/2016/2022 Windows Server 2008 R2 for x64-based Systems Service Pack 1/2 Windows Server 2004/2012/2012 R2/2016/2019/20H2/2022 (Server Core installation)
Solution
At present, the latest version has been officially released, please update the version in time, detailed link: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40444