ZeroHour

CVE-2021-33742

KEVmass

Out-of-Bounds Write RCE in Microsoft Windows MSHTML Engine (CVE-2021-33742)

CISA: Microsoft Windows MSHTML Platform Remote Code Execution Vulnerability

CVSS 3.1
7.5 high
EPSS
59%p99
Published
()
KEV added
AI analysis

A remote code execution vulnerability exists in the Microsoft Windows MSHTML Platform — the Internet Explorer/Trident rendering engine that Windows components and applications invoke to display web content — caused by an out-of-bounds write (CWE-787). An attacker triggers it by persuading a user to open attacker-controlled content, such as a crafted document or web page that causes MSHTML to render a remote URL; no privileges are required, but user interaction is needed and the attack is rated high complexity. Successful exploitation runs attacker code in the context of the logged-in user, potentially allowing installation of programs, viewing/changing/deleting data, or creating new accounts with the victim's rights. The affected range spans Windows 7, 8.1, RT 8.1, Windows 10 versions 1507 through 21H1, and Windows Server 2008 and 2012 — essentially the entire supported Windows installed base at the time of disclosure. Exploitation is confirmed in the wild: Microsoft disclosed the flaw as used in limited targeted attacks, CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03 (ransomware use unknown), and EPSS assigns a 59.4% 30-day exploitation probability (99th percentile).

What to do: Apply Microsoft's security update for CVE-2021-33742, delivered via the July 2021 cumulative Windows updates (and later), to all affected Windows 7/8.1/RT 8.1/10 clients and Windows Server 2008/2012 hosts, prioritizing internet-exposed systems and per CISA's required action. Because exploitation requires user interaction, treat unsolicited documents and links with caution until systems are patched. No public proof-of-concept is known, but the KEV listing confirms real-world targeted exploitation, so assume active scanning/attacks and verify patch status across the estate.

Affected
Microsoft Windows 101507, 1607, 1809, 1909, 2004, 20H2, 21H1
Microsoft Windows 7all supported editions (as listed by CISA)
Microsoft Windows 8.1all supported editions (as listed by CISA)
Microsoft Windows RT 8.1all supported editions (as listed by CISA)
Microsoft Windows Server 2008all supported editions (as listed by CISA)
Microsoft Windows Server 2012all supported editions (as listed by CISA)
Estimated exposure
masson the order of 1 billion+ Windows installations — The flaw affects nearly the entire Windows client and server line (Windows 7 through 10 21H1 and Server 2008/2012), and Microsoft has publicly reported more than a billion active Windows devices, so the potentially exposed installed base…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Windows MSHTML Platform Remote Code Execution Vulnerability

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 1909, windows 10 2004, windows 10 20h2, windows 10 21h1, windows 7, windows 8.1, windows rt 8.1, windows server 2008, windows server 2012
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news