Skip to content
OnMSFT.com
  • Home
  • About
  • Contact
  • News
  • How-to
  • Feature stories
  • Deals
  • Microsoft / office 365
  • Reviews
Menu
  • Home
  • About
  • Contact
  • News
  • How-to
  • Feature stories
  • Deals
  • Microsoft / office 365
  • Reviews
  1. Home
  2. News
  3. Microsoft acknowledges Windows zero-day vulnerability based on malicious Office files – onmsft.com

Microsoft acknowledges Windows zero-day vulnerability based on malicious Office files – onmsft.com

Rabia Noureen Rabia Noureen
September 8, 2021
2 min read

Microsoft has acknowledged a new zero-day vulnerability in all versions of Windows that is currently being exploited by attackers. The company says that a remote code execution vulnerability has been found in MSHTML, which can be used to create malicious Microsoft Office documents (via Bleeping Computer).

“An attacker could craft a malicious ActiveX control to be used by a Microsoft Office document that hosts the browser rendering engine. The attacker would then have to convince the user to open the malicious document. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights,” the company explained.

The remote code execution vulnerability, under the identifier CVE-2021-40444, was discovered by researchers from different cybersecurity companies, including Microsoft Security Response Center, EXPMON, and Mandiant. The vulnerability, when exploited, impacts the Internet Explorer’s browser rendering engine MSHTML, which is also used to render browser-based content in Microsoft Office files on Windows.

The Redmond giant is already working on a fix and plans to release a security update on this month’s Patch Tuesday or through an out-of-band update. In the meantime, users can protect PCs by keeping antimalware products (i.e., Microsoft Defender Antivirus and Defender for Endpoint) up to date. The company also advises users to disable the installation of ActiveX controls in Internet Explorer to mitigate any potential attack. We invite you to check out Microsoft’s Security Advisory page for more information about these workarounds.

Share This Post:

Share this article:
Tags:
Vulnerability Windows 10
Previous Article Razer’s new Halo Infinite Xbox and PC products unlock in-game content – onmsft.com Next Article What is Microsoft Start? Tips & Tricks for the Experience

Related Articles

Chrome tests Google Drive file uploads in the AI Mode compose box

April 14, 2026
Gemini image creation using right click desktop Chrome

Chrome lets you remake images with Gemini on desktop using just a right-click

April 13, 2026
Samsung Display crosses 5 million QD-OLED monitor shipments as demand grows fast, with new panels and strong premium market expansion worldwide.

Samsung Display Ships 5 Million QD-OLED Monitor Panels in Four Years

April 9, 2026

Leave a Comment Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Chrome tests Google Drive file uploads in the AI Mode compose box
  • Chrome lets you remake images with Gemini on desktop using just a right-click
  • Samsung Display Ships 5 Million QD-OLED Monitor Panels in Four Years
  • Intel Arc Pro B70 Teardown Reveals Blower Cooler and Early Board Design Details
  • Users Modify RTX 5090 Lightning Z Hardware to Unlock MSI’s Restricted 2500W BIOS

Recent Comments

  1. XxRIVTYxX on Intel Says It Tried to Help Before Crimson Desert Dropped Arc Support
  2. Gaurav Kumar on Chrome Prepares Nudge to ‘Move Tabs to the Side’ as Vertical Tabs Near Release
OnMSFT.com

The Tech News Site

Categories

  • Windows
  • Surface
  • Xbox
  • How-To
  • OnPodcast
  • Gaming
  • Edge
  • Teams

Recent Posts

  • Chrome tests Google Drive file uploads in the AI Mode compose box
  • Chrome lets you remake images with Gemini on desktop using just a right-click
  • Samsung Display Ships 5 Million QD-OLED Monitor Panels in Four Years
  • Intel Arc Pro B70 Teardown Reveals Blower Cooler and Early Board Design Details
  • Users Modify RTX 5090 Lightning Z Hardware to Unlock MSI’s Restricted 2500W BIOS

Quick Links

  • About OnMSFT.com
  • Contact OnMSFT
  • Join Our Team
  • Privacy Policy
© 2010–2026 OnMSFT.com LLC. All rights reserved.
About OnMSFT.comContact OnMSFTPrivacy Policy