Task for CVE-2021-40444 - MSHTML RCE

Greetings all. I’ve created a task for CVE-2021-40444 and the MSHTML RCE announced on the 7th. The task name is BPS - MSHTML CVE-2021-40444 and it’s available from my personal GitHub.

As evidenced above, this task creates the necessary registry keys. The Microsoft KB indicates that a system restart is necessary for these changes to take effect, which is not included with this content. Plan your remediation actions accordingly.

Finally, please note that this content is provided “as is” and without warranty.

5 Likes

Just seen this - I uploaded my versions to bigfix.me

One fixlet to apply the registry values, one to remove them again - just search for CVE-2021-4044.

6 Likes

thanks for uploading that to BigFix.me

my only suggestion is that we were not seeing it relevant to alot of machines because the registry hive does not exist on most of our machines. I modified the relevance to check and seems to be looking better in my environment

if exists (key “HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones” of native registry) then 4 != number of keys (“0”; “1”; “2”; “3”) whose (exists value “1001” whose (it as string as integer = 3) of it and exists value “1004” whose (it as string as integer = 3) of it) of key “HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones” of native registry else true

3 Likes

Thanks.

It hadn’t occurred to me that the …\Internet Settings\Zones key might not exist - we already have GPO to set some values for the Local Intranet zone, so the key already exists for us.

<trundles off to make the update />

3 Likes

Thanks for sharing the fixlet @trn. I added an action requires restart "CVE-2021-40444" to the action in the copy I made just to bring a visbility to machines that have now got the keys but need the restart to make it active

3 Likes