


Microsoft has identified a new zero-day vulnerability capable of attacking Windows 10 and certain versions of Windows Server systems. Microsoft has alerted users about this security flaw and suggested practical workarounds to reduce the risk of attacks. MiniTool Solution will present the newly discovered zero-day vulnerability from a few days ago and outline the practical mitigation strategies.
Hackers Can Exploit Your Windows Through CVE-2021-40444
Recently, a new zero-day vulnerability has been discovered. Hackers can utilize it to carry out attacks on Windows 10 and specific Windows Server machines. As of now, there is no official security update available to fix these systems. However, Microsoft has informed users about this security vulnerability and provided some helpful workarounds to mitigate the threat.
This new zero-day vulnerability is referred to as CVE-2021-40444. Hackers and attackers are exploiting it to execute code remotely on the targeted computer; even worse, they could gain full control over the PC.
A New Windows Print Spooler "PrintNightmare" Vulnerability Has Been Discovered.
Note: Developing a good practice of backing up the system and disk can help protect critical data from being lost due to disasters like unforeseen attacks. If your necessary files have already been lost before you had the opportunity to back them up, please use the following recovery software to retrieve them immediately.
Attackers Are Using Internet Explorer and Microsoft Office Documents
According to research, the security flaw CVE-2021-40444 can affect the MSHTML component in the Internet Explorer browser rendering engine running on Windows 10 and some Windows Server systems. However, if you believe you're safe because you never used Internet Explorer, you're mistaken. Why? Because Microsoft Office is also impacted by the remote code execution vulnerability.
The same vulnerable component—the rendering engine—is also utilized by Microsoft Office applications for rendering web-based content. Thus, if you inadvertently open trapped websites or specially crafted Microsoft Office documents, you'll become a victim.
- The MSHTML will load when users open Office documents (.docx file types).
- Subsequently, a specially crafted malicious webpage will appear.
- The ActiveX control will be employed to bring the system to download the malware payload.
Caution:
The MSHTML remote code execution vulnerability affects users with fewer privileges less than those with higher privileges.
You Can Obtain Admin Rights On Windows 10 With A Razer Mouse.
Microsoft Warned Windows Users About CVE-2021-40444 And Provided Mitigations
On the morning of Sunday, September 5, 2021, a researcher at EXPMON reported this Windows security vulnerability to Microsoft. Following this, Microsoft published the page “Microsoft MSHTML Remote Code Execution Vulnerability” on its website to explain CVE-2021-40444 and offer details on exploitability, mitigations, workarounds, and more. Rest assured, Microsoft is actively working on this issue and will release a security update to patch the vulnerability soon, either as part of the Patch Tuesday cycle or possibly as an out-of-band update beforehand.
All Windows 10 and Windows Server users should promptly implement mitigation measures until an official patch is released.
How to Mitigate the New Security Threat
Microsoft primarily suggests two approaches for mitigating CVE-2021-40444 at present.
#1. Update Antimalware Products
Users should ensure that Microsoft Defender Antivirus and Microsoft Defender for Endpoint are enabled and updated on their computers. Both products offer detection and protection against the known vulnerability.
- If you have already enabled Windows automatic updates, no additional action is required.
- For enterprise users who manage updates manually, they should opt for the detection build 1.349.22.0 or later and deploy it as soon as possible.
#2. Disable Internet Explorer ActiveX Controls
Microsoft stated that disabling the installation of all ActiveX controls in Internet Explorer effectively mitigates the known attack. Post this, the ActiveX controls previously installed on your PC won't expose this vulnerability, although they will continue to function.
Warning: Always back up your Registry before making any changes and exercise caution when editing the registries. Any errors could lead to severe issues requiring a reinstallation of your operating system. Use the Registry Editor at your own risk.
Steps to disable ActiveX controls via Group Policy:
- Open Group Policy Editor on Windows 10.
- Navigate to Computer Configuration -> Administrative Templates -> Windows Components -> Internet Explorer -> Internet Control Panel -> Security Page in the left pane.
- Double-click on Internet Zone in the right pane.
- Double-click Download signed ActiveX controls.
- Select Disabled and click OK.
- Repeat steps 3 through 5 for all zones in the list to fully secure your system.
Additionally, you can disable ActiveX controls on an individual system via regkey or disable preview in Windows Explorer to further enhance protection.
The above is the detailed content of A New Windows Zero-Day Vulnerability Is Found: CVE-2021-40444. For more information, please follow other related articles on the PHP Chinese website!

Hot AI Tools

Undress AI Tool
Undress images for free

Undresser.AI Undress
AI-powered app for creating realistic nude photos

AI Clothes Remover
Online AI tool for removing clothes from photos.

Clothoff.io
AI clothes remover

Video Face Swap
Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Article

Hot Tools

Notepad++7.3.1
Easy-to-use and free code editor

SublimeText3 Chinese version
Chinese version, very easy to use

Zend Studio 13.0.1
Powerful PHP integrated development environment

Dreamweaver CS6
Visual web development tools

SublimeText3 Mac version
God-level code editing software (SublimeText3)

This Google translate picture guide shows you how to translate text from an image. If you are looking for more computer tips and solutions, you can visit php.cn Software official website where you can also find some useful computer tools like php.cn

The operating system is the basic software for managing hardware resources, running programs, and providing user interaction interfaces. It coordinates the relationship between hardware and software and is responsible for memory allocation, device scheduling, file management and multitasking. Common systems include Windows (suitable for office and gaming), macOS (Apple devices, suitable for creative work), Linux (open source, suitable for developers), and Android/iOS (mobile device system). The choice of ordinary users depends on the usage scenario, such as software compatibility, security and customization requirements. How to view system information: Use winver command for Windows, click on the machine for macOS, use terminal commands for Linux, and find the phone in settings. The operating system is the underlying tool for daily use,

Have you ever wanted to adjust computer settings to fix some issues but suffered from Control Panel not opening? There is nothing more frustrating than this app not turning on, stopping you from viewing and changing system settings. In this post, mul

What is Dell Digital Locker? How to log into Dell Digital Locker? This post from php.cn provides answers. Besides, you can know how to use your Dell Digital Locker to find software products included with your Dell computer.

This essay summarized by php.cn Software mainly teaches you how to open Windows 11 Computer Management with Windows Search, Quick Link menu, Run dialog, command prompt, PowerShell, File Explorer, Control Panel, as well as a desktop shortcut.

AMD offers an AMD Driver Auto-Detect Tool to help users automatically download and update the drivers of the installed AMD products. Check how to download AMD Driver Auto-detect Tool on Windows 10/11 and how to use it to get the latest AMD drivers. F

What is Airplane Mode on iPhone? What does Airplane Mode do on iPhone? How to turn it on your iPhone? When to use it? This post from php.cn introduces information about iPhone Airplane Mode.

People usually access restricted websites that are blocked in their region via VPN. But what if you encounter the VPN not working on Chrome? That can really drive you crazy. Fortunately, you can find a couple of useful solutions in this guide. Get st
