Headline
CVE-2021-40444: Microsoft MSHTML Remote Code Execution Vulnerability
By default, Microsoft Office opens documents from the internet in Protected View or Application Guard for Office both of which prevent the current attack.
- For information about Protected View, see What is Protected View?.
- For information about Application Guard for Office, see Application Guard for Office.
Customers of Microsoft Defender for Endpoint can enable attack surface reduction rule “BlockOfficeCreateProcessRule” that blocks Office apps from creating child processes. Creating malicious child processes is a common malware strategy. For more information see Use attack surface reduction rules to prevent malware infection.