Linchakin

Exploitation of the CVE-2021-40444 vulnerability in MSHTML

 September 17, 2021     No comments   

Summary

Last week, Microsoft reported the remote code execution vulnerability CVE-2021-40444 in the MSHTML browser engine. According to the company, this vulnerability has already been used in targeted attacks against Microsoft Office users. In attempt to exploit this vulnerability, attackers create a document with a specially-crafted object. If a user opens the document, MS Office will download and execute a malicious script.
According to our data, the same attacks are still happening all over the world. We are currently seeing attempts to exploit the CVE-2021-40444 vulnerability targeting companies in the research and development sector, the energy sector and large industrial sectors, banking and medical technology development sectors, as well as telecommunications and the IT sector. Due to its ease of exploitation and the few published Proof-of-Concept (PoC), we expect to see an increase in attacks using this vulnerability.

Geography of CVE-2021-40444 exploitation attempts

Kaspersky is aware of targeted attacks using CVE-2021-40444, and our products protect against attacks leveraging the vulnerability. Possible detection names are:

  • HEUR:Exploit.MSOffice.CVE-2021-40444.a
  • HEUR:Trojan.MSOffice.Agent.gen
  • PDM:Exploit.Win32.Generic


Killchain generated by KEDR during execution of CVE-2021-40444 Proof-of-Concept

Experts at Kaspersky are monitoring the situation closely and improving mechanisms to detect this vulnerability using Behavior Detection and Exploit Prevention components. Within our Managed Detection and Response service, our SOC experts are able to detect when this vulnerability is expoited, investigate such attacks and notify customers.

Technical details

The remote code execution vulnerability CVE-2021-40444 was found in MSHTML, the Internet Explorer browser engine which is a component of modern Windows systems, both user and server. Moreover, the engine is often used by other programs to work with web content (e.g. MS Word or MS PowerPoint).
In order to exploit the vulnerability, attackers embed a special object in a Microsoft Office document containing an URL for a malicious script. If a victim opens the document, Microsoft Office will download the malicious script from the URL and run it using the MSHTML engine. Then the script can use ActiveX controls to perform malicious actions on the victim’s computer. For example, the original zero-day exploit which was used in targeted attacks at the time of detection used ActiveX controls to download and execute a Cobalt Strike payload. We are currently seeing various types of malware, mostly backdoors, which are delivered by exploiting the CVE-2021-40444 vulnerability.

Mitigations

IoC

MD5
ef32824c7388a848c263deb4c360fd64
e58b75e1f588508de7c15a35e2553b86
e89dbc1097cfb8591430ff93d9952260

URL
hidusi[.]com
103.231.14[.]134

Adblock test (Why?)


You may be interested in:
>> Is a Chromebook worth replacing a Windows laptop?
>> Find out in detail the outstanding features of Google Pixel 4a
>> Top 7 best earbuds you should not miss

Related Posts:
>> Recognizing 12 Basic Body Shapes To Choose Better Clothes
>>Ranking the 10 most used smart technology devices
>> Top 5+ Best E-readers: Compact & Convenient Pen
  • Share This:  
  •  Facebook
  •  Twitter
  •  Google+
  •  Stumble
  •  Digg
Email ThisBlogThis!Share to XShare to Facebook

Related Posts:

  • 6th Sep - Dollar function in excelDollar function in excel is a specialized function that is used to convert the given value to currency in dollar format. It only introduces dollar sym… Read More
  • Raspberry Pi Broadcasts UHF Channels to CRT TVsByAsh Hill Maker Devicemodder2 has created a wireless Raspberry Pi-based CRT TV broadcaster using a Ras...It's not quite the same as running your own TV station and broadcasting episodes of Conan the Librarian to everyone in town, but this Raspberry Pi pro… Read More
  • 6th Sep - Left formula in excelThe left function is used to extract the characters from the left side of the string. The specified characters can be in the form of numbers, characte… Read More
  • Live Wallpaper HD 5.1.0 – Desktop weather & screensaverby NMac Ked Live Wallpaper HD offers a selection of beautiful, themed scenes that will add life to your desktop. From cityscapes and sunsets to far a… Read More
  • n-Track Studio Suite 9.1.4.4127 – Audio and MIDI multitrack recorderby NMac Ked n-Track Studio Suite is an audio and MIDI multitrack recorder that turns your Mac into a full-fledged recording studio. You can record an… Read More
Newer Post Older Post Home

0 Comments:

Post a Comment


Copyright © 2025 Linchakin | Powered by Blogger
Design by Hardeep Asrani | Blogger Theme by NewBloggerThemes.com | Distributed By Gooyaabi Templates