Cybercriminals are sharing tutorials and exploits for the Windows MSHTML zero-day vulnerability (CVE-2021-40444) on hacking forums, enabling other hackers to begin exploiting the new vulnerability.
See also: Microsoft has fixed a vulnerability in Azure Container Instances

Last week, Microsoft disclosed a new zero-day vulnerability in Windows MSHTML. The vulnerability allows attackers to create malicious documents, including Office and RTF documents, to remotely execute commands on a victim's computer.
There are still no security updates available for the CVE-2021-40444. The zero-day vulnerability was discovered by the EXPMON and security firm Mandiant , and Microsoft decided to disclose the vulnerability and provide some advice to prevent its exploitation.
To avoid a potential attack, one should block ActiveX controls and Word/RTF document previews in Windows Explorer.
Windows MSHTML zero-day: Guides and PoCs have been published on hacking forums
When Microsoft first disclosed the zero-day vulnerability (CVE-2021-40444) in Windows MSHTML, security researchers quickly found the malicious documents used in attacks.
The researchers were able to reproduce the attacks and modify the exploits for further capabilities, but did not disclose details to prevent other cybercriminals from exploiting them.
See also: New DNS vulnerability allows for 'state-level espionage'
Unfortunately, attackers managed to reproduce the exploit themselves and malicious sample documents were published online along with tutorials and PoCs.
Since last week, criminals have been sharing information about the exploit's HTML component and how to create the malicious document. On Friday, more instructions were published on how to create the payload and a CAB file that included the path traversal vulnerability component.

On Saturday, as researchers began posting more details on Github and Twitter, the criminals shared more details about how they created all aspects of the exploit.
The information is simple and allows anyone to create their own working version of the zero-day vulnerability CVE-2021-40444, including a python server for distributing malicious documents and CAB files.
Windows MSHTML zero-day: Defense
Fortunately, there is some good news in this case. Since the vulnerability was disclosed, Microsoft Defender and other security programs can detect and block malicious documents and CAB files used in this attack.
Microsoft has also provided the following instructions for blocking ActiveX controls in Internet Explorer and document previews in Windows Explorer.
See also: Windows Update: Does it tell you if your PC can run Windows 11?
Disabling ActiveX controls in Internet Explorer
Follow these steps:
Open Notepad and paste the following text into a text file. Then save the file as disable-activex.reg. Make sure you have enabled the display of file extensions for the correct creation of the Registry file.
Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0] "1001"=dword:00000003 "1004"=dword:00000003 [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] "1001"=dword:00000003 "1004"=dword:00000003 [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] "1001"=dword:00000003 "1004"=dword:00000003 [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] "1001"=dword:00000003 "1004"=dword:00000003Find the newly created disable-activex.reg and double-click on it. When a UAC message appears, click on the “Yes” button to import the Registry entries.
Restart your computer to apply the new configuration .
After restarting, ActiveX controls will be disabled in Internet Explorer.
You can re-enable ActiveX controls by deleting the above Registry keys.

Disabling document previews in Windows Explorer
Security researchers also found that the Windows MSHTML zero-day vulnerability can be exploited by viewing a malicious document using the preview feature.
For this reason, Microsoft also suggested disabling preview in RTF and Word documents.
In the Registry Editor (regedit.exe) go to the appropriate registry key:
For Word documents:
- HKEY_CLASSES_ROOT.docx\ShellEx{8895b1c6-b41f-4c1c-a562-0d564250836f}
- HKEY_CLASSES_ROOT.doc\ShellEx{8895b1c6-b41f-4c1c-a562-0d564250836f}
- HKEY_CLASSES_ROOT.docm\ShellEx{8895b1c6-b41f-4c1c-a562-0d564250836f}
For RTF documents:
- HKEY_CLASSES_ROOT.rtf\ShellEx{8895b1c6-b41f-4c1c-a562-0d564250836f}
Export a copy of the Registry key as a backup.
Now double-click on Name and delete the Value Data in the Edit String dialog window.
Click OK.
Previews are now disabled in Windows Explorer.
These two measures will help prevent an attack, but users are still at risk until an official security update is released.
Source: Bleeping Computer
