Sploitus

CVE-2021-40444

38 known exploits for CVE-2021-40444

<p>Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using specially-crafted Microsoft Office documents.</p> <p>An attacker could craft a malicious ActiveX control to be used by a Microsoft Office document that hosts the browser rendering engine. The attacker would then have to convince the user to open the malicious document. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</p> <p>Microsoft Defender Antivirus and Microsoft Defender for Endpoint both provide detection and protections for the known vulnerability. Customers should keep antimalware products up to date. Customers who utilize automatic updates do not need to take additional action. Enterprise customers who manage updates should select the detection build 1.349.22.0 or newer and deploy it across their environments. Microsoft Defender for Endpoint alerts will be displayed as: “Suspicious Cpl File Execution”.</p> <p>Upon completion of this investigation, Microsoft will take the appropriate action to help protect our customers. This may include providing a security update through our monthly release process or providing an out-of-cycle security update, depending on customer needs.</p> <p>Please see the <strong>Mitigations</strong> and <strong>Workaround</strong> sections for important information about steps you can take to protect your system from this vulnerability.</p> <p><strong>UPDATE</strong> September 14, 2021: Microsoft has released security updates to address this vulnerability. Please see the Security Updates table for the applicable update for your system. We recommend that you install these updates immediately. Please see the FAQ for important information about which updates are applicable to your system.</p>

Microsoft Windows 10 1507
< 10.0.10240.19060
Microsoft Windows 10 1607
< 10.0.14393.4651
Microsoft Windows 10 1809
< 10.0.17763.2183
Microsoft Windows 10 1909
< 10.0.18363.1801
Microsoft Windows 10 2004
< 10.0.19041.1237
Microsoft Windows 10 20h2
< 10.0.19042.1237
Fix
Available
CVSS 3.1
8.8 HIGH
EPSS
97.2% (100th percentile)
Weakness
CWE-22
NVD status
Analyzed
Published
2021-09-15
CVE-2021-40444 at NVD
Authoritative description, scoring and affected products

38 known exploits for CVE-2021-40444

Proof-of-concept code and exploit modules indexed by Sploitus

Exploit for Reliance on Untrusted Inputs in a Security Decision in Microsoft
2026-02-04 decalage2GITHUB
Exploit for Path Traversal in Microsoft
2025-09-06 热门极速下载GITEE
Exploit for Path Traversal in Microsoft
2025-09-06 热门极速下载GITEE
Exploit for Path Traversal in Microsoft
2024-07-28 basim-ahmadGITHUB
Exploit for Path Traversal in Microsoft
2023-06-05 hqdat809GITHUB
Exploit for CVE-2022-30190
2022-06-02 gyaansastraGITHUB
Exploit for CVE-2022-30190
2022-06-01 PwnC00reGITHUB
Exploit for CVE-2022-30190
2022-06-01 sudoazaGITHUB
Exploit for CVE-2022-30190
2022-05-31 bytecapsGITHUB
Exploit for CVE-2022-30190
2022-05-31 doocopGITHUB
Exploit for CVE-2022-30190
2022-05-31 archanchoudhuryGITHUB
Microsoft Office MSDT Follina Proof Of Concept
2022-05-31 JMousqueton, github.comPACKETSTORM
Exploit for CVE-2022-30190
2022-05-30 JMousquetonGITHUB
Exploit for Path Traversal in Microsoft
2021-12-28 MRacumenGITHUB
Exploit for Path Traversal in Microsoft
2021-12-19 34zYGITHUB
Microsoft Office Word MSHTML Remote Code Execution
2021-12-09 LockedByte, Ramella Sebastien, thesunRider, klezVirus, metasploit.comPACKETSTORMRuby
Microsoft Office Word MSHTML Remote Code Execution Exploit
2021-12-09 metasploitZDTRuby
Microsoft Office Word Malicious MSHTML RCE
2021-12-09 lockedbyte, klezVirus, thesunRider, mekhalleh (RAMELLA Sébastien)METASPLOITRuby
Exploit for Path Traversal in Microsoft
2021-11-25 lisinan988GITHUB
Exploit for Path Traversal in Microsoft
2021-11-22 Alexcot25051999GITHUB
Exploit for Path Traversal in Microsoft
2021-11-06 末心aGITEE
Exploit for Path Traversal in Microsoft
2021-10-28 0xK4guraGITHUB
Exploit for Path Traversal in Microsoft
2021-10-28 wh00datzGITHUB
Exploit for Path Traversal in Microsoft
2021-10-28 kagura-maruGITHUB
Exploit for Path Traversal in Microsoft
2021-10-24 TiagoSergioGITHUB
Exploit for Path Traversal in Microsoft
2021-10-09 kawasaki_najGITEE
Exploit for Path Traversal in Microsoft
2021-10-08 妖道GITEE
Exploit for Path Traversal in Microsoft
2021-10-03 H0j3nGITHUB
Exploit for Path Traversal in Microsoft
2021-10-03 zyjsuperGITEE
CVE-2021-40444 PoC - Malicious docx generator to exploit CVE-2021-40444 (Microsoft Office Word Remote Code Execution)
2021-09-16 KitPloitKITPLOIT
Exploit for Path Traversal in Microsoft
2021-09-15 klezVirusGITHUB
Exploit for Path Traversal in Microsoft
2021-09-14 k8gegeGITHUB
Exploit for Path Traversal in Microsoft
2021-09-12 mortalsGITEE
Exploit for Path Traversal in Microsoft
2021-09-12 aslitsecurityGITHUB
Exploit for Path Traversal in Microsoft
2021-09-11 fengjixuchuiGITHUB
Exploit for Path Traversal in Microsoft
2021-09-10 lockedbyteGITHUB
Exploit for Path Traversal in Microsoft
2021-09-09 DarkSpringsGITHUB
Exploit for Path Traversal in Microsoft
2021-09-09 Immersive-Labs-SecGITHUB