#CVE-2021-40444

Vulnerability/Target

2021-11-09 • 북한 정찰총국 해킹 조직, 한국 싱크탱크 사칭으로 국방,안보전문가 표적 공격!

Microsoft Windows MSHTML contains a remote-code-execution vulnerability that was targeted through specially crafted Microsoft Office documents. An attacker can craft a malicious ActiveX control for an Office document that hosts the browser rendering engine and must convince a user to open the document; code executes with the user's rights, so lower-privileged accounts are less affected than administrative accounts.

https://www.cve.org/CVERecord?id=CVE-2021-40444

Tagged Reports

« Back