Emergency Vulnerability Bulletin

9/10/21 1:21 PM  |  by RedLegg Blog

Microsoft MSHTML Remote Code Execution Vulnerability

Identifier: CVE-2021-40444

Exploit or POC: Yes


Description: CVE-2021-40444 allows an attacker to remotely execute code on a host via the vulnerable MSHTML component. This vulnerability is actively being exploited and being used to install CobaltStrike payloads onto vulnerable hosts.

Mitigation recommendation: RedLegg recommends patching this vulnerability as soon as possible. Microsoft has offered alternative mitigation steps if patching is not possible at this time.

Get Blog Updates

Related Articles

Patch Tuesday Recap - March 2023 threat intel, 96bravo, Bulletin

Patch Tuesday Recap - March 2023

About: In an effort to provide additional value to our customers RedLegg will be releasing monthly security bulletins ...
Emergency Vulnerability Bulletin - 02/06/23 threat intel, 96bravo, Bulletin

Emergency Vulnerability Bulletin - 02/06/23

About: RedLegg will occasionally communicate vulnerabilities released outside the usual release schedule to provide ...
Critical Security Vulnerabilities Bulletin