I’ve been slammed for the past few days, and haven’t kept you folks apprised of the latest Internet Explorer 0day. It depends on you opening an infect
[See the full post at: That Internet Explorer XXE zero day poking through to Edge]
![]() |
There are isolated problems with current patches, but they are well-known and documented on this site. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
That Internet Explorer XXE zero day poking through to Edge
Home » Forums » Newsletter and Homepage topics » That Internet Explorer XXE zero day poking through to Edge
- This topic has 16 replies, 9 voices, and was last updated 3 years, 11 months ago.
Tags: 0patch Edge Internet Explorer XXE 0day
AuthorTopicViewing 5 reply threadsAuthorReplies-
anonymous
Guest -
Paul T
AskWoody MVP
-
MikeMc
AskWoody Lounger-
woody
Manager
GoneToPlaid
AskWoody Lounger-
GoneToPlaid
AskWoody Lounger -
warrenrumak
AskWoody Lounger -
b
ManagerNo, but with extensions hidden by default a file could be named reader.txt.mht and appear as only reader.txt.
(I’ve always thought that’s the craziest default ever, and I unhide extensions on any computer I touch.)
Windows 11 Pro version 22H2 build 22621.1485 + Microsoft 365 + Edge
-
warrenrumak
AskWoody LoungerYou still had to choose to download the file from an unknown source, and you had to choose to open it.
If an attacker can convince you to do that, they probably could convince you to download and run an executable. Or a Powershell script. Or a batch file. Or a vbs file. Or a malicious RAR file that targets WinRAR.
Also, one would presume that most of the major AV vendors already have a heuristics check in place that’ll detect this particular attack. Inspecting and flagging dodgy MHT files something they’ve been doing for almost 20 years…. it’s hardly new ground.
-
-
b
ManagerA few observations:
1. Not using IE doesn’t help, as long as it’s enabled and associated with .mht and/or .mhtml files.
Fred Langa says today; “Even if you never use IE, never click on it, or never call it up in any way, it’s there, and this new exploit can make use of it. In fact, if you use any version of Windows, you almost surely have IE on your PC.” Microsoft Windows users take note
2. The exploit can only read and transmit a named file from a known location. The proof of concept used c:\windows\system.ini which is probably identical on billions of computers. Which file on my computer would you like to read which could subject me to some form of future danger or even privacy invasion?
3. The original author said the exploit proof of concept had also been tested on Windows 7 and Server 2012 R2, but perhaps that was with an HTM file previously downloaded via Edge on Windows 10?
Windows 11 Pro version 22H2 build 22621.1485 + Microsoft 365 + Edge
1 user thanked author for this post.
-
woody
Manager -
GoneToPlaid
AskWoody Lounger
Microfix
AskWoody MVPAre these file associations safe to use in a different browser as defaults?
i.e. Chrome, Chromium, Palemoon, Waterfox, Firefox, Opera etc.. have the facility to change these associations to the aforementioned browser.
As it only mentions IE and Edge, no others.Keeping IT Lean, Clean and Mean!-
b
ManagerMy understanding is that Firefox, Palemoon, Waterfox may be less than ideal because Firefox can’t actually open .mht/.mhtml files (as Mozilla Archive Format extension went away), so will offer to open them in IE (defeating the purpose).
I believe Chrome, Chromium, Opera would be fine. (I’ve associated Chromium Edge Dev, which can open .mht/.mhtml files.)
Others have associated with Word, which can open .mht/.mhtml files (Word 2003 or later).
But for anyone without a special use for MHT files, Notepad.exe is probably good enough.
Windows 11 Pro version 22H2 build 22621.1485 + Microsoft 365 + Edge
1 user thanked author for this post.
-
mn–
AskWoody LoungerI note that Chrome doesn’t seem to register itself as a handler for these normally but some other Chromium-derived browsers do.
However… it’d seem that if you happen to have preview pane on, it’ll render these with IE for that anyway regardless of the association? Not sure about thumbnail generation, didn’t get a thumbnail for my quick test .mhtml but…
-
anonymous
GuestViewing 5 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Are you checking your backup tonight?
by
Susan Bradley
2 hours, 38 minutes ago -
Old Microsoft ‘opt-in’ fix exploited in 3CX attack
by
Microfix
9 hours, 35 minutes ago -
Brave’s Lost Mouseover
by
Casey H
7 hours, 26 minutes ago -
Court ordered GitHub to disclose users leaking Twitter code
by
Alex5723
10 hours, 46 minutes ago -
Italy bans chatGPT over privacy.
by
Alex5723
12 hours, 7 minutes ago -
Windows 11 Insider Preview build 25330 released to Canary
by
joep517
13 hours, 21 minutes ago -
Windows 11 Insider Preview build 23424 released to DEV
by
joep517
13 hours, 24 minutes ago -
Betterbird updates
by
Alex5723
16 hours, 52 minutes ago -
Windows 2000 – Windows 11 Not Responding Prompts!
by
Alex5723
23 hours, 36 minutes ago -
40+ macOS Keyboard Shortcuts you NEED to know
by
Alex5723
23 hours, 26 minutes ago -
backup web hotmail to local drive.
by
Oberon
22 hours, 41 minutes ago -
Vinyl nostalgia
by
Microfix
2 hours, 21 minutes ago -
March 31st is world backup day.
by
Alex5723
23 hours, 4 minutes ago -
Using an iPad and replying with a selected quote
by
WCHS
1 day, 4 hours ago -
Plex Media Server support ending for older versions of…
by
Alex5723
1 day, 11 hours ago -
BingBang: The AAD misconfiguration in Azure Active Directory
by
Alex5723
1 day, 12 hours ago -
May I add another HD to my tower?
by
Rush2112
8 hours, 2 minutes ago -
Pwn2Own: Tesla 3 infotainment hacked in 2 minutes
by
Alex5723
1 day, 19 hours ago -
Another Windows media creation tool? Sure, why not.
by
Alex5723
2 days, 11 hours ago -
Microsoft Defender : Legit URLs marked as malicious
by
Alex5723
1 day, 9 hours ago -
Refurbished HP ProBook
by
Kathy Stevens
7 hours, 38 minutes ago -
Microsoft PC Manager (beta) updates
by
Alex5723
1 day, 17 hours ago -
Ubuntu Cinnamon becomes an official flavor, making Linux Mint obsolete
by
Alex5723
14 hours, 35 minutes ago -
HDMI KVM switch for DP
by
freelab23
3 days, 1 hour ago -
My Experience with Win 11 ver 22H2
by
agoldhammer
3 days, 8 hours ago -
Email from Mail on my iPhone to Gmail address failed
by
DrRon
9 hours, 7 minutes ago -
Can’t Update Win 10 past 21H2
by
cmndo97
3 days, 10 hours ago -
Revo Uninstaller (freeware) Updates
by
Microfix
17 hours, 13 minutes ago -
The Third deployment phase for CVE-2022-37967 starts April 11, 2023
by
Alex5723
3 days, 10 hours ago -
Firefox to support Windows 7 and 8 systems well into 2024 at least
by
Alex5723
2 days, 19 hours ago
Recent blog posts
- Are you checking your backup tonight?
- MS-DEFCON 4: Win11 22H2 not ready for prime time
- Apple zero days fixed today
- You’re fired if you don’t know how to use GPT-4
- Microsoft 365 Copilot announced
- What’s wrong with OneNote — and what you can fix
- Temp_Cleaner GUI — Just what I was looking for
- Who controls our tech?
Key Links
S | M | T | W | T | F | S |
---|---|---|---|---|---|---|
1 | ||||||
2 | 3 | 4 | 5 | 6 | 7 | 8 |
9 | 10 | 11 | 12 | 13 | 14 | 15 |
16 | 17 | 18 | 19 | 20 | 21 | 22 |
23 | 24 | 25 | 26 | 27 | 28 | 29 |
30 |
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2023 by AskWoody Tech LLC. All Rights Reserved.