Netskope Threat Labs

CVE-2021-40444

ATP Sandbox Adv. HeuristicsAVNetskope IPS

CVE-2021-40444 is a remote code execution vulnerability in Microsoft Windows MSHTML that cyberattackers exploit via malicious Office documents to download and execute malware. A crafted document embedded a remote object that the rendering engine would process, allowing arbitrary code to run with no macros and minimal user interaction. State sponsored actors used the flaw in targeted campaigns within weeks of disclosure, and criminal groups adopted it soon after.

First seen
January 2022
Last seen
October 2026
Alert Name
Binary.Exploit.CVE-2021-40444
Document-HTML.Exploit.CVE-2021-40444
Document-Office.Exploit.CVE-2021-40444
Document-Word.Exploit.CVE-2021-40444
Document-XML.Exploit.CVE-2021-40444
Document.Exploit.CVE-2021-40444
Email-MIME.Exploit.CVE-2021-40444
Exploit.CVE-2021-40444.Gen.1
Exploit.CVE-2021-40444.Gen.2
Exploit.CVE-2021-40444.Gen.4