Skip to content
OnMSFT.com
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
Menu
  • Home
  • About
  • Contact
  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Edge
  • Teams
  • Gaming
  1. Home
  2. News
  3. Microsoft acknowledges Windows zero-day vulnerability based on malicious Office files – OnMSFT.com

Microsoft acknowledges Windows zero-day vulnerability based on malicious Office files – OnMSFT.com

Rabia Noureen Rabia Noureen
September 8, 2021
2 min read

Microsoft has acknowledged a new zero-day vulnerability in all versions of Windows that is currently being exploited by attackers. The company says that a remote code execution vulnerability has been found in MSHTML, which can be used to create malicious Microsoft Office documents (via Bleeping Computer).

“An attacker could craft a malicious ActiveX control to be used by a Microsoft Office document that hosts the browser rendering engine. The attacker would then have to convince the user to open the malicious document. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights,” the company explained.

The remote code execution vulnerability, under the identifier CVE-2021-40444, was discovered by researchers from different cybersecurity companies, including Microsoft Security Response Center, EXPMON, and Mandiant. The vulnerability, when exploited, impacts the Internet Explorer’s browser rendering engine MSHTML, which is also used to render browser-based content in Microsoft Office files on Windows.

The Redmond giant is already working on a fix and plans to release a security update on this month’s Patch Tuesday or through an out-of-band update. In the meantime, users can protect PCs by keeping antimalware products (i.e., Microsoft Defender Antivirus and Defender for Endpoint) up to date. The company also advises users to disable the installation of ActiveX controls in Internet Explorer to mitigate any potential attack. We invite you to check out Microsoft’s Security Advisory page for more information about these workarounds.

Share This Post:

Share this article:
Tags:
Vulnerability Windows 10
Previous Article Razer’s new Halo Infinite Xbox and PC products unlock in-game content – OnMSFT.com Next Article What is Microsoft Start? Tips & Tricks for the Experience

Related Articles

Chrome May Soon Open Your Webcam for Photo Uploads on Desktop

March 5, 2026

Chrome Tests Reading Mode for Text-Heavy PDFs

March 5, 2026

YouTube App Shows Ads That Won’t Close During Fullscreen Videos

March 4, 2026

Leave a Comment Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Chrome May Soon Open Your Webcam for Photo Uploads on Desktop
  • Chrome Tests Reading Mode for Text-Heavy PDFs
  • YouTube App Shows Ads That Won’t Close During Fullscreen Videos
  • TikTok Confirms DMs Will Not Get End-to-End Encryption
  • OpenAI GPT-5.3 Instant released, when will you get it, and benchmarks

Recent Comments

No comments to show.
OnMSFT.com

OnMSFT.com covers Microsoft news, reviews, and how-to guides. Formerly known as WinBeta, we have been your source for Microsoft news since 1998.

Categories

  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Gaming
  • Edge
  • Teams

Recent Posts

  • Chrome May Soon Open Your Webcam for Photo Uploads on Desktop
  • Chrome Tests Reading Mode for Text-Heavy PDFs
  • YouTube App Shows Ads That Won’t Close During Fullscreen Videos
  • TikTok Confirms DMs Will Not Get End-to-End Encryption
  • OpenAI GPT-5.3 Instant released, when will you get it, and benchmarks

Quick Links

  • About OnMSFT.com
  • Contact OnMSFT
  • Join Our Team
  • Privacy Policy
© 2010–2026 OnMSFT.com LLC. All rights reserved.
About OnMSFT.comContact OnMSFTPrivacy Policy