Microsoft Windows MSHTML RCE

Strike ID:
E21-ckkc1
CVSS:
7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
False Positive:
f
Variants:
2
Year:
2021

Description

This strike exploits a remote code execution vulnerability in Microsoft Windows MSHTML. The vulnerability is due to improper validation of Office documents. An attacker could entice the victim to open a crafted docx file which contains a malicious ActiveX control or an RTF file with an \objupdate control that references public resources and can be abused to execute malicious code from the Internet while the document is being loaded. Successful exploitation could lead to code execution on the victim's machine.

CVE

References