Microsoft
MSHTML
Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.
This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.
A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.
CVE-observed version history
| CVE | Published | Affected versions | Fixed version information | Publisher evidence |
|---|---|---|---|---|
| CVE-2021-40444 | 15 Sep 2021 | Windows 10 Version 1507: 10.0.10240.0 < 10.0.10240.19060; Windows 10 Version 1607: 10.0.14393.0 < 10.0.14393.4651; Windows 10 Version 1809: 10.0.17763.0 < 10.0.17763.2183, 10.0.0 < 10.0.17763.2183; Windows 10 Version 1909: 10.0.0 < 10.0.18363.1801; Windows 10 Version 2004: 10.0.0 < 10.0.19041.1237; Windows 10 Version 20H2: 10.0.0 < 10.0.19042.1237; Windows 10 Version 21H1: 10.0.0 < 10.0.19043.1237; Windows 7: 6.1.0 < 6.1.7601.25712; Windows 7 Service Pack 1: 6.1.0 < 6.1.7601.25712; Windows 8.1: 6.3.0 < 6.3.9600.20120; Windows Server 2008 R2 Service Pack 1: 6.1.7601.0 < 6.1.7601.25712; Windows Server 2008 R2 Service Pack 1 (Server Core installation): 6.1.7601.0 < 6.1.7601.25712; Windows Server 2008 Service Pack 2: 6.0.6003.0 < 6.0.6003.21218; Windows Server 2008 Service Pack 2 (Server Core installation): 6.0.6003.0 < 6.0.6003.21218; Windows Server 2012: 6.2.9200.0 < 6.2.9200.23462; Windows Server 2012 (Server Core installation): 6.2.9200.0 < 6.2.9200.23462; Windows Server 2012 R2: 6.3.9600.0 < 6.3.9600.20120; Windows Server 2012 R2 (Server Core installation): 6.3.9600.0 < 6.3.9600.20120; Windows Server 2016: 10.0.14393.0 < 10.0.14393.4651; Windows Server 2016 (Server Core installation): 10.0.14393.0 < 10.0.14393.4651; Windows Server 2019: 10.0.17763.0 < 10.0.17763.2183; Windows Server 2019 (Server Core installation): 10.0.17763.0 < 10.0.17763.2183; Windows Server 2022: 10.0.20348.0 < 10.0.20348.230; Windows Server version 2004: 10.0.0 < 10.0.19041.1237; Windows Server version 20H2: 10.0.0 < 10.0.19042.1237 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2019-0541 | 8 Jan 2019 | Microsoft Office: 2010 Service Pack 2 (32-bit editions), 2010 Service Pack 2 (64-bit editions), 2013 RT Service Pack 1, 2013 Service Pack 1 (32-bit editions), 2013 Service Pack 1 (64-bit editions), 2016 (32-bit edition), 2016 (64-bit edition), 2019 for 32-bit editions, 2019 for 64-bit editions; Microsoft Office Word Viewer: Microsoft Office Word Viewer; Internet Explorer 9: Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for x64-based Systems Service Pack 2; Internet Explorer 11: Windows 10 for 32-bit Systems, Windows 10 for x64-based Systems, Windows 10 Version 1607 for 32-bit Systems, Windows 10 Version 1607 for x64-based Systems, Windows 10 Version 1703 for 32-bit Systems, Windows 10 Version 1703 for x64-based Systems, Windows 10 Version 1709 for 32-bit Systems, Windows 10 Version 1709 for ARM64-based Systems, Windows 10 Version 1709 for x64-based Systems, Windows 10 Version 1803 for 32-bit Systems, Windows 10 Version 1803 for ARM64-based Systems, Windows 10 Version 1803 for x64-based Systems, Windows 10 Version 1809 for 32-bit Systems, Windows 10 Version 1809 for ARM64-based Systems, Windows 10 Version 1809 for x64-based Systems, Windows 7 for 32-bit Systems Service Pack 1, Windows 7 for x64-based Systems Service Pack 1, Windows 8.1 for 32-bit systems, Windows 8.1 for x64-based systems, Windows RT 8.1, Windows Server 2008 R2 for x64-based Systems Service Pack 1, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019; Microsoft Excel Viewer: 2007 Service Pack 3; Internet Explorer 10: Windows Server 2012; Office: 365 ProPlus for 32-bit Systems, 365 ProPlus for 64-bit Systems | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
How this record is maintained
The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.