CVE-2021-34448
KEVmassMemory Corruption in Microsoft Windows Scripting Engine (In-the-Wild Exploitation)
CISA: Microsoft Windows Scripting Engine Memory Corruption Vulnerability
CVE-2021-34448 is a memory corruption flaw (out-of-bounds write, CWE-787) in Microsoft's Windows Scripting Engine, the component that executes scripts such as JScript and VBScript on Windows. It is triggered when the engine mishandles objects in memory while processing crafted script content, typically through user interaction such as viewing a malicious web page or opening a document containing crafted script. Successful exploitation can corrupt memory in a way that lets an attacker execute code in the context of the current user, giving the attacker the victim's privileges on the machine. Essentially every Windows client and server ships the scripting engine, so the affected population is effectively all unpatched Microsoft Windows systems; exploitation is confirmed in the wild, with CISA adding the flaw to its KEV catalog on 2021-11-03 and an unusually high EPSS of 40.1% (99th percentile) indicating elevated near-term exploitation risk, though no ransomware association is confirmed and no public proof-of-concept is known. Remediation is through the vendor's Windows security updates addressing this CVE.
What to do: Apply the Microsoft Windows security updates that fix CVE-2021-34448 (delivered via Windows Update in Microsoft's November 2021 release cycle) to all Windows clients and servers, prioritizing endpoints used interactively for web browsing and document handling, as CISA KEV requires prompt federal remediation. Verify each system's installed cumulative update includes the fix for this CVE before treating it as remediated. Until patched, reduce risk by limiting exposure to untrusted web content and documents (e.g., minimizing use of legacy Internet Explorer and scripting hosts) and monitor for suspicious activity involving Windows scripting components.
| Microsoft Windows | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Scripting Engine Memory Corruption Vulnerability
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1809, windows 10 1909, windows 10 2004, windows 10 20h2, windows 10 21h1, windows 7, windows 8.1, windows rt 8.1, windows server 2008, windows server 2012
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N