Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-69088
HistorySep 08, 2021 - 12:00 a.m.

Microsoft MSHTML Remote Code Execution Vulnerability

2021-09-0800:00:00
China National Vulnerability Database
www.cnvd.org.cn
20

0.968 High

EPSS

Percentile

99.7%

MSHTML (also known as Trident) is Microsoft’s Internet Explorer browser engine, and while MHTML is primarily used in the deprecated Internet Explorer browser, the component is also used in Office applications to render Word, Excel, or PowerPoint documents in A remote code execution vulnerability exists in Microsoft MSHTML. An attacker could exploit this vulnerability by crafting a Microsoft Office document with a malicious ActiveX control and tricking a user into opening the document. A remote attacker who successfully exploits this vulnerability could execute arbitrary code on the target system with that user’s privileges.

CPENameOperatorVersion
microsoft windowseq8.1