CVE-2021-40444

HIGH KEV RANSOMWARE

Microsoft Office Word Malicious MSHTML RCE

Title source: metasploit
STIX 2.1

Exploitation Summary

CVE-2021-40444 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added November 3, 2021, with confirmed use in ransomware campaigns. EIP tracks 45 public exploits from researchers including lockedbyte, klezVirus, aslitsecurity, including a Metasploit module exploits/windows/fileformat/word_mshtml_rce.

AI-analyzed exploit summary This repository contains a functional proof-of-concept exploit for CVE-2021-40444, a Microsoft Office Word Remote Code Execution vulnerability. It generates a malicious docx file and hosts an exploit server to deliver a payload (e.g., a DLL) via a crafted CAB file.

Description

<p>Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using specially-crafted Microsoft Office documents.</p> <p>An attacker could craft a malicious ActiveX control to be used by a Microsoft Office document that hosts the browser rendering engine. The attacker would then have to convince the user to open the malicious document. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</p> <p>Microsoft Defender Antivirus and Microsoft Defender for Endpoint both provide detection and protections for the known vulnerability. Customers should keep antimalware products up to date. Customers who utilize automatic updates do not need to take additional action. Enterprise customers who manage updates should select the detection build 1.349.22.0 or newer and deploy it across their environments. Microsoft Defender for Endpoint alerts will be displayed as: “Suspicious Cpl File Execution”.</p> <p>Upon completion of this investigation, Microsoft will take the appropriate action to help protect our customers. This may include providing a security update through our monthly release process or providing an out-of-cycle security update, depending on customer needs.</p> <p>Please see the <strong>Mitigations</strong> and <strong>Workaround</strong> sections for important information about steps you can take to protect your system from this vulnerability.</p> <p><strong>UPDATE</strong> September 14, 2021: Microsoft has released security updates to address this vulnerability. Please see the Security Updates table for the applicable update for your system. We recommend that you install these updates immediately. Please see the FAQ for important information about which updates are applicable to your system.</p>

Exploits (45)

nomisec WORKING POC 1,714 stars
by lockedbyte · client-side
https://github.com/lockedbyte/CVE-2021-40444

This repository contains a functional proof-of-concept exploit for CVE-2021-40444, a Microsoft Office Word Remote Code Execution vulnerability. It generates a malicious docx file and hosts an exploit server to deliver a payload (e.g., a DLL) via a crafted CAB file.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Office Word (2013-2021)
No auth needed
Prerequisites: Python 3 · lcab · DLL payload · HTTP server
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 823 stars
by klezVirus · client-side
https://github.com/klezVirus/CVE-2021-40444

This repository contains a fully weaponized exploit for CVE-2021-40444, a Microsoft Office Word Remote Code Execution vulnerability. It includes a generator for malicious docx files that leverage a CAB file with a ZipSlip vulnerability to achieve arbitrary code execution via DLL side-loading.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Microsoft Office Word (pre-patch versions)
No auth needed
Prerequisites: Victim opens a malicious docx file · Microsoft Office Word with vulnerable version · Network access to a controlled server hosting malicious files
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 170 stars
by aslitsecurity · client-side
https://github.com/aslitsecurity/CVE-2021-40444_builders

This repository contains a working proof-of-concept exploit for CVE-2021-40444, a remote code execution vulnerability in Microsoft Office. The exploit generates malicious documents and files to trigger the vulnerability via crafted CAB files and Office documents.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Office (MSHTML)
No auth needed
Prerequisites: Microsoft Office installation · Crafted malicious document or CAB file
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 104 stars
by Edubr2020 · poc
https://github.com/Edubr2020/CVE-2021-40444--CABless

This PoC demonstrates CVE-2021-40444 by exploiting a Microsoft Office MSHTML vulnerability via a crafted HTML file and a RAR archive containing a WSF script. The attack leverages ActiveX to execute arbitrary code without requiring a CAB archive.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Office (MSHTML)
No auth needed
Prerequisites: Victim must open the malicious HTML file · RAR archive with embedded WSF script must be accessible
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 66 stars
by 34zY · client-side
https://github.com/34zY/Microsoft-Office-Word-MSHTML-Remote-Code-Execution-Exploit

This is a Metasploit module that generates a malicious DOCX file exploiting CVE-2021-40444, a Microsoft Office Word MSHTML RCE vulnerability. It crafts a malicious ActiveX control to achieve remote code execution on vulnerable Windows systems.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Office Word (vulnerable versions)
No auth needed
Prerequisites: Vulnerable Microsoft Office Word installation · User interaction to open the malicious DOCX file
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP 19 stars
by k8gege · poc
https://github.com/k8gege/CVE-2021-40444

This repository provides a detailed writeup and usage instructions for exploiting CVE-2021-40444, a Microsoft MSHTML remote code execution vulnerability. It includes steps for generating malicious DLLs, creating exploit documents, and executing payloads via Office files.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Office (2019 and others) on Windows 7/8/8.1/10, Windows Server 2008-2022
No auth needed
Prerequisites: Ladon toolkit · Access to generate and host malicious files · Victim interaction to open the malicious document
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP 16 stars
by ozergoker · poc
https://github.com/ozergoker/CVE-2021-40444

This repository provides a writeup and mitigation steps for CVE-2021-40444, a Microsoft MSHTML Remote Code Execution vulnerability. It includes registry modifications to disable ActiveX controls in Internet Explorer as a workaround.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Theoretical
Target: Microsoft MSHTML (Internet Explorer)
No auth needed
Prerequisites: Victim must open a malicious Office document or visit a malicious webpage
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 13 stars
by mansk1es · poc
https://github.com/mansk1es/Caboom

This PoC exploits CVE-2021-40444, a remote code execution vulnerability in Microsoft MSHTML via a malicious ActiveX control in a crafted Office document. It generates a malicious .cab file by embedding a DLL or INF file and modifying offset bytes to trigger the vulnerability.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft MSHTML (Internet Explorer)
No auth needed
Prerequisites: A crafted DLL or INF file · CABARC.EXE utility · Victim interaction to open the malicious document
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 9 stars
by kagura-maru · poc
https://github.com/kagura-maru/CVE-2021-40444-POC

This repository provides a proof-of-concept for CVE-2021-40444, a Microsoft MSHTML Remote Code Execution vulnerability. It uses Metasploit to generate a malicious DLL payload and embeds it in a Word document to achieve RCE via a reverse TCP shell.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft MSHTML (Internet Explorer)
No auth needed
Prerequisites: Metasploit Framework · Python 3 · msfvenom · HTTP server for hosting payload
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 9 stars
by H0j3n · client-side
https://github.com/H0j3n/CVE-2021-40444

This repository contains a Python script (`gen.py`) that automates the generation of malicious Microsoft Office documents exploiting CVE-2021-40444, a remote code execution vulnerability in MSHTML. The script modifies a .docx file to include a malicious payload hosted on a remote server, leveraging obfuscation techniques like HTML entity encoding and UTF-16BE encoding.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Office (MSHTML)
No auth needed
Prerequisites: A modified .docx file with an embedded Bitmap Object · A payload (.dll) · A web server to host the malicious files
devstral-2 · analyzed Feb 16, 2026 Full analysis →
github WORKING POC 8 stars
by codecat007 · cpoc
https://github.com/codecat007/cvehub/tree/main/windows/CVE-2021-40444

This repository contains a functional exploit for CVE-2021-40444, a Microsoft Office Word Remote Code Execution vulnerability. It includes scripts to generate malicious DOCX files and a server to host the exploit payload, demonstrating the vulnerability by executing arbitrary DLLs.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Office Word
No auth needed
Prerequisites: DLL payload · HTTP server to host exploit files · Target system with vulnerable Microsoft Office Word
devstral-2 · analyzed Feb 27, 2026 Full analysis →
nomisec WRITEUP 7 stars
by DarkSprings · poc
https://github.com/DarkSprings/CVE-2021-40444

The repository contains only a README.md file with a public key and minimal information about CVE-2021-40444, lacking any functional exploit code or technical details. It appears to be a placeholder or incomplete documentation.

Classification
Writeup 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: Microsoft MSHTML (Internet Explorer)
No auth needed
Prerequisites: None specified
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP 5 stars
by LazarusReborn · poc
https://github.com/LazarusReborn/Docx-Exploit-2021

This repository contains a README describing a .docx exploit related to CVE-2021-40444, which leverages malicious files embedded in .docx resources. No actual exploit code is provided.

Classification
Writeup 30%
Attack Type
Rce
Complexity
Moderate
Reliability
Theoretical
Target: Microsoft Office (specific version unclear)
No auth needed
Prerequisites: Victim interaction to open the malicious .docx file
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP 4 stars
by fengjixuchui · poc
https://github.com/fengjixuchui/CVE-2021-40444-docx-Generate

This repository provides a writeup on generating a malicious .docx file to exploit CVE-2021-40444, a Microsoft Office Word Remote Code Execution vulnerability. It describes the process of inserting a 'Bitmap Image' object to trigger the exploit.

Classification
Writeup 80%
Attack Type
Rce
Complexity
Moderate
Reliability
Theoretical
Target: Microsoft Office Word
No auth needed
Prerequisites: Microsoft Office Word installation · ability to deliver malicious .docx file to target
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP 3 stars
by vysecurity · poc
https://github.com/vysecurity/CVE-2021-40444

The repository contains only a README.md file with minimal content, lacking any exploit code or technical details. It appears to be a placeholder or stub for CVE-2021-40444, a known Microsoft MSHTML Remote Code Execution vulnerability.

Classification
Writeup 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: Microsoft MSHTML (Internet Explorer)
No auth needed
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 3 stars
by bambooqj · client-side
https://github.com/bambooqj/CVE-2021-40444_EXP_JS

This exploit leverages CVE-2021-40444, a remote code execution vulnerability in Microsoft MSHTML via a malicious ActiveX control. It uses a series of HTML file manipulations and ActiveX object instantiations to trigger the vulnerability and execute arbitrary code.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft MSHTML (Internet Explorer)
No auth needed
Prerequisites: Victim must visit a malicious webpage or open a malicious document
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 2 stars
by MRacumen · client-side
https://github.com/MRacumen/CVE-2021-40444

This repository contains a fully weaponized exploit for CVE-2021-40444, a Microsoft Office Word Remote Code Execution vulnerability. It includes a generator for malicious DOCX files that leverage a CAB file with a path traversal vulnerability to achieve arbitrary code execution via DLL side-loading.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Microsoft Office Word (pre-patch versions)
No auth needed
Prerequisites: Victim opens a malicious DOCX file · Microsoft Office Word with vulnerable version · Network access to attacker-controlled server for payload delivery
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 1 stars
by Zeop-CyberSec · client-side
https://github.com/Zeop-CyberSec/word_mshtml

This is a Metasploit auxiliary module that generates a malicious DOCX file exploiting CVE-2021-40444, a vulnerability in Microsoft Office's MSHTML engine. It crafts a malicious ActiveX control to achieve remote code execution when the document is opened.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Office Word (vulnerable versions)
No auth needed
Prerequisites: Vulnerable version of Microsoft Office Word · Ability to deliver the malicious DOCX file to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec STUB 1 stars
by k4k4 · poc
https://github.com/k4k4/CVE-2021-40444-Sample

The repository contains only a README.md file with minimal information about CVE-2021-40444, lacking any exploit code or technical details. It appears to be a placeholder or stub without functional content.

Classification
Stub 10%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: Microsoft MSHTML (Internet Explorer)
No auth needed
devstral-2 · analyzed Feb 16, 2026 Full analysis →
gitlab WORKING POC
by helsecert_pocs · poc
https://gitlab.com/helsecert_pocs/cve-2021-40444

This repository contains a proof-of-concept for CVE-2021-40444, including malicious document files (docx, RTF) and supporting files (HTML, CAB) designed to exploit the vulnerability. The README indicates these files can be used for testing detection and mitigation measures.

Classification
Working Poc 80%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Office (MSHTML)
No auth needed
Prerequisites: Victim interaction (opening malicious document) · Network access to deliver payload
devstral-2 · analyzed Feb 23, 2026 Full analysis →
nomisec WORKING POC
by basim-ahmad · client-side
https://github.com/basim-ahmad/Follina-CVE-and-CVE-2021-40444

This repository contains a Python-based PoC for CVE-2021-40444, a Microsoft Office RCE vulnerability. It includes tools to parse and manipulate CAB files, generate malicious documents, and exploit the vulnerability via a logical bug.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Office (MSHTML)
No auth needed
Prerequisites: Victim interaction to open a malicious document · Network access to a controlled server for payload delivery
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by hqdat809 · client-side
https://github.com/hqdat809/CVE-2021-40444

This repository contains a functional PoC for CVE-2021-40444, a Microsoft Office Word RCE vulnerability. It generates a malicious docx file and hosts an exploit server to deliver a payload (e.g., a DLL) via a crafted CAB file.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Office Word (2013-2021)
No auth needed
Prerequisites: Python 3 · lcab · DLL payload · HTTP server
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP
by nvchungkma · poc
https://github.com/nvchungkma/CVE-2021-40444-Microsoft-Office-Word-Remote-Code-Execution-

The repository contains only a README.md file with minimal content, lacking any exploit code or technical details. It appears to be a placeholder or incomplete writeup for CVE-2021-40444.

Classification
Writeup 10%
Attack Type
Other
Complexity
Theoretical
Reliability
Theoretical
Target: Microsoft Office Word
No auth needed
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by lisinan988 · poc
https://github.com/lisinan988/CVE-2021-40444-exp

This repository contains a functional exploit for CVE-2021-40444, a Microsoft Office Word Remote Code Execution vulnerability. It generates a malicious docx file and hosts an exploit server to deliver a payload (DLL) via a crafted CAB file.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Office Word (2013-2021)
No auth needed
Prerequisites: Python 3 · lcab · DLL payload · HTTP server
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by Alexcot25051999 · poc
https://github.com/Alexcot25051999/CVE-2021-40444

This repository contains a functional proof-of-concept exploit for CVE-2021-40444, a Microsoft Office Word Remote Code Execution vulnerability. It generates a malicious docx file and hosts a server to deliver the payload, leveraging a patched CAB file and obfuscated HTML exploit.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Office Word (2013-2021)
No auth needed
Prerequisites: DLL payload (e.g., calc.dll) · Python 3 · lcab tool · HTTP server
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by tiagob0b · poc
https://github.com/tiagob0b/CVE-2021-40444

This repository contains a fully weaponized exploit for CVE-2021-40444, a Microsoft Office Word Remote Code Execution vulnerability. It includes a generator for malicious DOCX files that leverage a CAB file with a ZipSlip vulnerability to achieve arbitrary code execution via DLL side-loading.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Microsoft Office Word (pre-patch versions)
No auth needed
Prerequisites: Victim opens a malicious DOCX file · Microsoft Office Word with vulnerable version · Network access to a controlled server hosting malicious files
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by kal1gh0st · client-side
https://github.com/kal1gh0st/CVE-2021-40444_CAB_archives

This PoC generates malicious CAB archives exploiting CVE-2021-40444 by embedding a modified DLL and crafting a CAB file with a patched header to trigger remote code execution via Microsoft MSHTML.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Windows (MSHTML Engine)
No auth needed
Prerequisites: Windows OS with makecab utility · Victim interaction to open the malicious CAB file
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by Jeromeyoung · poc
https://github.com/Jeromeyoung/TIC4301_Project

This repository provides a proof-of-concept exploit for CVE-2021-40444, a remote code execution vulnerability in Microsoft MSHTML. It includes instructions for setting up a vulnerable Windows 10 environment and a Kali Linux attacker machine, generating a malicious DLL, and delivering the exploit via a crafted document.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft MSHTML (Internet Explorer)
No auth needed
Prerequisites: Vagrant with Kali Linux and Windows 10 boxes · Metasploit for payload generation · Python 3 for exploit script
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by metehangenel · poc
https://github.com/metehangenel/MSHTML-CVE-2021-40444

This repository contains a functional proof-of-concept exploit for CVE-2021-40444, a remote code execution vulnerability in Microsoft Office via MSHTML. It includes tools to generate malicious documents, deobfuscate exploit code, and compile a malicious DLL for payload delivery.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Office (MSHTML component)
No auth needed
Prerequisites: Target must open a malicious Office document · Attacker must host a malicious CAB file and HTML exploit
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by Phuong39 · poc
https://github.com/Phuong39/CVE-2021-40444-CAB

This PoC exploits CVE-2021-40444 by crafting malicious CAB files with embedded commands or DLLs. It uses MakeCAB to generate a CAB file with a patched header to trigger the vulnerability in Microsoft Windows.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Windows (via CAB file parsing)
No auth needed
Prerequisites: Windows environment with MakeCAB utility · Ability to deliver malicious CAB file to target
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec STUB
by Jeromeyoung · poc
https://github.com/Jeromeyoung/MSHTMHell

The repository contains only a README and a Python script with ASCII art, lacking any functional exploit code for CVE-2021-40444. It appears to be a placeholder or incomplete PoC.

Classification
Stub 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: Microsoft Office (CVE-2021-40444)
No auth needed
Prerequisites: None identified due to lack of functional code
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by Immersive-Labs-Sec · client-side
https://github.com/Immersive-Labs-Sec/cve-2021-40444-analysis

This is a deobfuscated exploit for CVE-2021-40444, a remote code execution vulnerability in Microsoft Office. The exploit leverages ActiveX objects and path traversal to execute malicious code via a crafted document.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Office (MSHTML Engine)
No auth needed
Prerequisites: Victim must open a malicious Office document · Internet access to fetch payload
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP
by jamesrep · poc
https://github.com/jamesrep/cve-2021-40444

This repository provides a detailed analysis of the CVE-2021-40444 exploit chain, including the malicious Word document and associated files. It explains the multi-stage attack involving OLE objects, ActiveX, and a malicious .cab file leading to code execution.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Office (MSHTML Engine)
No auth needed
Prerequisites: Victim opens malicious Word document · Internet access to download .cab file
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by W1kyri3 · poc
https://github.com/W1kyri3/Exploit-PoC-CVE-2021-40444-inject-ma-doc-vao-docx

This repository contains a functional PoC for CVE-2021-40444, a Microsoft Office Word RCE vulnerability. It generates a malicious docx file and hosts an exploit server to deliver a payload (DLL) via a crafted CAB file.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Office Word (2013-2021)
No auth needed
Prerequisites: lcab installed · Python 3 · DLL payload (e.g., calc.dll)
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP
by KnoooW · poc
https://github.com/KnoooW/CVE-2021-40444-docx-Generate

This repository provides a step-by-step guide to exploit CVE-2021-40444, a Microsoft Office Word Remote Code Execution vulnerability, by manipulating a .docx file's internal structure. It describes the process of embedding a malicious object and modifying XML relationships to trigger the exploit.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Office Word (versions affected by CVE-2021-40444)
No auth needed
Prerequisites: Ability to craft a malicious .docx file · Victim interaction to open the file
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by lockedbyte, klezVirus, thesunRider, mekhalleh (RAMELLA Sébastien) · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/word_mshtml_rce.rb

This Metasploit module exploits CVE-2021-40444 by crafting a malicious DOCX file that leverages an ActiveX control to trigger remote code execution via the MSHTML engine in Microsoft Office Word. The exploit generates a CAB file with a manipulated checksum and hosts it via an HTTP server to deliver the payload.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Office Word (vulnerable versions)
No auth needed
Prerequisites: Vulnerable Microsoft Office Word installation · User interaction to open the malicious DOCX file
devstral-2 · analyzed Feb 16, 2026 Full analysis →
patchapalooza WORKING POC
by Moxin1044 · poc
https://gitee.com/Moxin1044/CVE-2021-40444

This repository contains a functional exploit for CVE-2021-40444, a Microsoft Office Word Remote Code Execution vulnerability. It includes tools to generate malicious documents and a server to host the exploit payload.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Office Word
No auth needed
Prerequisites: DLL payload · HTTP server to host exploit files
devstral-2 · analyzed Feb 23, 2026 Full analysis →
patchapalooza WORKING POC
by joecool0 · poc
https://gitee.com/joecool0/CVE-2021-40444

This repository contains a functional exploit for CVE-2021-40444, a Microsoft Office Word Remote Code Execution vulnerability. It includes scripts to generate a malicious docx file and host an exploit server, leveraging a logical bug to execute arbitrary DLLs.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Office Word
No auth needed
Prerequisites: DLL payload · HTTP server to host exploit files
devstral-2 · analyzed Feb 23, 2026 Full analysis →
patchapalooza WORKING POC
by xiaocainiao149 · poc
https://gitee.com/xiaocainiao149/CVE-2021-40444

This repository contains a fully weaponized exploit for CVE-2021-40444, a Microsoft Office Word Remote Code Execution vulnerability. It includes a malicious docx generator, CAB file manipulation tools, and detailed technical analysis of the exploit chain involving path traversal and DLL side-loading.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Microsoft Office Word
No auth needed
Prerequisites: malicious DLL · CAB file manipulation · HTML file >= 4096 bytes
devstral-2 · analyzed Feb 23, 2026 Full analysis →
patchapalooza WORKING POC
by mirrors_trending · poc
https://gitee.com/mirrors_trending/CVE-2021-40444_1

This repository contains a fully weaponized exploit for CVE-2021-40444, a Microsoft Office Word RCE vulnerability. It includes a malicious docx generator, CAB file manipulation tools, and a detailed technical analysis of the exploit chain, including overlooked requirements like HTML size and CAB file byte-patching.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Microsoft Office Word
No auth needed
Prerequisites: Malicious DLL file · Access to target's network to host malicious files
devstral-2 · analyzed Feb 23, 2026 Full analysis →
patchapalooza WORKING POC
by zyjsuper · poc
https://gitee.com/zyjsuper/CVE-2021-40444

This repository contains a functional exploit for CVE-2021-40444, a Microsoft Office Word Remote Code Execution vulnerability. It includes scripts to generate a malicious docx file and host an exploit server, leveraging a patched CAB file and obfuscated HTML to achieve arbitrary DLL execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Office Word (2013-2021)
No auth needed
Prerequisites: DLL payload · Python 3 · lcab utility · HTTP server
devstral-2 · analyzed Feb 23, 2026 Full analysis →
patchapalooza SUSPICIOUS
by aydianosec · client-side
https://github.com/aydianosec/CVE2021-40444

The repository contains only a README with links to external resources (malware samples and other repos) but no actual exploit code or technical details. This is characteristic of a social engineering lure.

Classification
Suspicious 90%
Attack Type
Other
Complexity
Theoretical
Reliability
Theoretical
Target: Microsoft Office (CVE-2021-40444)
No auth needed
Prerequisites: none provided
devstral-2 · analyzed Feb 23, 2026 Full analysis →
patchapalooza WORKING POC
by mirrors_trending · poc
https://gitee.com/mirrors_trending/CVE-2021-40444

This repository contains a functional exploit for CVE-2021-40444, a Microsoft Office Word Remote Code Execution vulnerability. It includes tools to generate a malicious docx file and a server to host the exploit, leveraging a patched CAB file and obfuscated HTML to achieve arbitrary DLL execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Office Word (2013-2021)
No auth needed
Prerequisites: DLL payload · Python 3 · lcab utility · HTTP server
devstral-2 · analyzed Feb 23, 2026 Full analysis →
patchapalooza WORKING POC
by evaltx · poc
https://gitee.com/evaltx/CVE-2021-40444

This repository contains a functional exploit for CVE-2021-40444, a Microsoft Office Word Remote Code Execution vulnerability. It includes scripts to generate a malicious docx file and host an exploit server, leveraging a patched CAB file and obfuscated HTML to trigger the vulnerability.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Office Word (2013-2021)
No auth needed
Prerequisites: DLL payload · Python 3 · lcab tool · HTTP server
devstral-2 · analyzed Feb 23, 2026 Full analysis →

Scores

CVSS v3 8.8
EPSS 0.9433
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2021-11-03
VulnCheck KEV 2021-09-07
InTheWild.io 2021-09-07
ENISA EUVD EUVD-2021-27621
Ransomware Use Confirmed
CWE
CWE-22
Status published
Products (18)
microsoft/windows_10_1507 < 10.0.10240.19060
microsoft/windows_10_1607 < 10.0.14393.4651
microsoft/windows_10_1809 < 10.0.17763.2183
microsoft/windows_10_1909 < 10.0.18363.1801
microsoft/windows_10_2004 < 10.0.19041.1237
microsoft/windows_10_20h2 < 10.0.19042.1237
microsoft/windows_10_21h1 < 10.0.19043.1237
microsoft/windows_7
microsoft/windows_8.1
microsoft/windows_rt_8.1
... and 8 more
Published Sep 15, 2021
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026