CVE-2021-40444
Exploited in the Wild
✓ Confirmed 0-Day
★ Google Project Zero
Triaged: March 3, 2026
13 articles
EPSS Score
Source: FIRST.org · 2026-05-24
94.33%
probability
This CVE has a 94.33% probability
of being exploited in the next 30 days.
0%
Top 100.0th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Description
Project ZeroUnspecified remote code execution in MSHTML
Attack Intelligence
Google Project Zero
Patched
Sept. 14, 2021
Reported by
Rick Cole (MSTIC), Dhanesh Kizhakkinan of Mandiant, Genwei Jiang of Mandiant, Haifei Li of EXPMON, and Byce Abdo of Mandiant
Root Cause Analysis
???
Exploits & PoC
lockedbyte/CVE-2021-40444
CVE-2021-40444 PoC
1731
klezVirus/CVE-2021-40444
CVE-2021-40444 - Fully Weaponized Microsoft Office Word RCE Exploit
824
Edubr2020/CVE-2021-40444--CABless
Modified code so that we don´t need to rely on CAB archives
104
66
H0j3n/CVE-2021-40444
PoC CVE-2021-40444 — H0j3n/CVE-2021-40444
9
5 repos — triés par ⭐
Rechercher sur GitHub ↗
New Microsoft Office zero-day used in attacks to execute PowerShell
BleepingComputer
May 30, 2022
Microsoft September 2021 Patch Tuesday fixes 2 zero-days, 60 flaws
BleepingComputer
Sep 14, 2021
Defense Lessons From the Black Basta Ransomware Playbook
Qualys
Feb 25, 2025
Windows MSHTML zero-day used in malware attacks for over a year
BleepingComputer
Jul 10, 2024
Microsoft fixes Windows CVE-2021-40444 MSHTML zero-day bug
BleepingComputer
Sep 14, 2021
Windows MSHTML zero-day defenses bypassed as new info emerges
BleepingComputer
Sep 09, 2021
Qualys Response to CISA Alert: Binding Operational Directive 22-01
Qualys
Nov 09, 2021
Security Advisory 2021-047
CERT-EU
Sep 08, 2021
Signal Intelligence
Confidence
92%
EPSS
94.33%
Mentions
13
Last Seen
Feb 25, 2025
CNA Information
Analyst Note
CVE-2021-40444 is a confirmed MSHTML remote code execution vulnerability with high CVSS score (8.8) that Microsoft officially acknowledged with evidence of active exploitation in the wild through malicious Office documents. The vulnerability was reported by Google Project Zero and covered by reputable security media, with documented targeted attacks occurring before public disclosure, establishing strong confirmation of both existence and real-world exploitation.
Threat Actors 21
MuddyWater
apt_group
Information theft and espionage
🇮🇷 IR
Turla Group
apt_group
Information theft and espionage
Russian Federation
APT 29
apt_group
Information theft and espionage
🇷🇺 RU
DarkHotel
apt_group
Information theft and espionage
🇰🇷 KR
Kimsuky
apt_group
Information theft and espionage
🇰🇷 KR
SaintBear
apt_group
Information theft and espionage
🇷🇺 RU
CHRYSENE
apt_group
Information theft and espionage
🇮🇷 IR
Harvester
apt_group
Information theft and espionage
Unknown
FusionCore
apt_group
🇪🇺 EU
MAGNALLIUM
apt_group
Sabotage and destruction
🇮🇷 IR
DNSpionage
apt_group
Information theft and espionage
🇮🇷 IR
ELECTRUM
apt_group
Information theft and espionage
🇷🇺 RU
VICEROY TIGER
apt_group
Information theft and espionage
🇮🇳 IN
TA413
apt_group
Information theft and espionage
🇨🇳 CN
RomCom
apt_group
Financial gain
🇷🇺 RU
Fox Kitten
apt_group
Information theft and espionage
🇮🇷 IR
GreenCharlie
apt_group
Information theft and espionage
🇮🇷 IR
Void Banshee
apt_group
unknown
TRACER KITTEN
apt_group
Information theft and espionage
🇮🇷 IR
WildPressure
apt_group
Information theft and espionage
UNKNOWN
Ferocious Kitten
apt_group
Information theft and espionage
🇮🇷 IR
Triage Info
Decided atMar 03, 2026