ZeroHour
Security Affairspublished ()ingested @securityaffairs

Security Affairs Malware Newsletter

highMalwareimportance 47CVE-2021-40444

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-40444
Remote Code Execution via MSHTML Rendering Engine in Microsoft Windows/Office (CVE-2021-40444)

CVE-2021-40444 is a remote code execution vulnerability in the Microsoft MSHTML browser rendering engine, which Microsoft Office documents can load on Windows systems. It is triggered when a user is convinced to open a specially crafted Office document containing a malicious ActiveX control hosted by the MSHTML engine (tracked as a path-traversal-class issue, CWE-22). A successful attacker gains the ability to run arbitrary code in the context of the logged-on user, with greater impact when that user has administrative rights. Any Windows system that can open Office documents is exposed, spanning Windows 7, 8.1, RT 8.1, Windows 10 (1507 through 21H1) and Windows Server 2004/2008. Exploitation is confirmed in the wild: Microsoft observed targeted attacks at disclosure, the flaw is in CISA's KEV with known ransomware use, and Microsoft released security updates on September 14, 2021.

Do: Apply Microsoft's security updates released September 14, 2021 for your Windows version immediately; this is a CISA KEV item with known ransomware use, so patching is treated as mandatory. As interim protection, keep Microsoft Defender Antivirus/Defender for Endpoint signatures current (enterprise detection build 1.349.22.0 or newer, with alerts appearing as 'Suspicious Cpl File Execution') and avoid opening untrusted Office documents, since exploitation requires user interaction with a crafted file.

8.897% KEV ransomware PoC ×2
  • microsoft MSHTML as shipped in the affected Windows releases
  • microsoft Windows 10 1507, 1607, 1809, 1909, 2004, 20H2, 21H1
  • microsoft Windows 7 all versions covered by Microsoft's September 2021 security updates
  • +4 more
masshundreds of millions of Windows PCs and servers (nearly all Windows desktop/laptop installs on affected versions at disclosure)
Full article227 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini July 07, 2024

Today marks the launch of the Security Affairs newsletter, specializing in Malware. This newsletter complements the weekly one you already receive. Each week, it will feature a collection of the best articles and research on malware.

CapraTube Remix | Transparent Tribe’s Android Spyware Targeting Gamers, Weapons Enthusiasts

Supply Chain Compromise Leads to Trojanized Installers for Notezilla, RecentX, Copywhiz 

Caught in the Net: Using Infostealer Logs to Unmask CSAM Consumers       

I am Goot (Loader)

Exposing FakeBat loader: distribution methods and adversary infrastructure

MerkSpy: Exploiting CVE-2021-40444 to Infiltrate Systems 

Xctdoor Malware Used in Attacks Against Korean Companies (Andariel)  

Supposed Grasshopper: Operators Impersonate Israeli Government And Private Companies To Deploy Open-Source Malware

Eldorado Ransomware: The New Golden Empire of Cybercrime?     

Meet Brain Cipher — The new ransomware behind Indonesia’s data center attack  

Exploring the Infection Chain: ScreenConnect’s Link to AsyncRAT Deployment  

Fake IT support sites push malicious PowerShell scripts as Windows fixes

New Threat: A Deep Dive Into the Zergeca Botnet   Supply Chain Compromise Leads to Trojanized Installers for Notezilla, RecentX, Copywhiz

Follow me on LinkedIn and subscribe to the Newsletter to receive it for free every week.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/165406/malware/security-affairs-malware-newsletter-round-1.html