Australian Cyber Security Centre
Background /What has happened?
A vulnerability (CVE-2021-40444) has been identified in MSHTML, a component present in all installations of Microsoft Windows. A cyber actor could use a malicious ActiveX control in a Microsoft Office document to exploit this vulnerability. This malicious document would then likely be used as part of a spearphishing campaign.
Microsoft has identified that this vulnerability is currently being exploited.
/Public Release. View in full here.



