I’ve been slammed for the past few days, and haven’t kept you folks apprised of the latest Internet Explorer 0day. It depends on you opening an infect
[See the full post at: That Internet Explorer XXE zero day poking through to Edge]
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
That Internet Explorer XXE zero day poking through to Edge
Home » Forums » Newsletter and Homepage topics » That Internet Explorer XXE zero day poking through to Edge
- This topic has 16 replies, 9 voices, and was last updated 6 years ago.
Tags: 0patch Edge Internet Explorer XXE 0day
AuthorTopicViewing 5 reply threadsAuthorRepliesMikeMc
AskWoody LoungerApril 18, 2019 at 8:41 am #541656GoneToPlaid
AskWoody LoungerApril 18, 2019 at 9:46 am #542988-
GoneToPlaid
AskWoody Lounger -
warrenrumak
AskWoody Lounger -
b
AskWoody_MVPApril 18, 2019 at 12:12 pm #546381 -
warrenrumak
AskWoody LoungerApril 18, 2019 at 2:53 pm #549782You still had to choose to download the file from an unknown source, and you had to choose to open it.
If an attacker can convince you to do that, they probably could convince you to download and run an executable.ย Or a Powershell script.ย Or a batch file.ย Or a vbs file.ย Or a malicious RAR file that targets WinRAR.
Also, one would presume that most of the major AV vendors already have a heuristics check in place that’ll detect this particular attack.ย Inspecting and flagging dodgy MHT files something they’ve been doing for almost 20 years…. it’s hardly new ground.
-
-
b
AskWoody_MVPApril 18, 2019 at 10:47 am #544292A few observations:
1. Not using IE doesn’t help, as long as it’s enabled and associated with .mht and/or .mhtml files.
Fred Langa says today; “Even if you never use IE, never click on it, or never call it up in any way, itโs there, and this new exploit can make use of it. In fact, if you use any version of Windows, you almost surely have IE on your PC.” Microsoft Windows users take note
2. The exploit can only read and transmit a named file from a known location. The proof of concept used c:\windows\system.ini which is probably identical on billions of computers. Which file on my computer would you like to read which could subject me to some form of future danger or even privacy invasion?
3. The original author said the exploit proof of concept had also been tested on Windows 7 and Server 2012 R2, but perhaps that was with an HTM file previously downloaded via Edge on Windows 10?
1 user thanked author for this post.
-
woody
Manager -
GoneToPlaid
AskWoody LoungerApril 18, 2019 at 11:29 am #545362
Microfix
AskWoody MVPApril 18, 2019 at 1:07 pm #547642Are these file associations safe to use in a different browser as defaults?
i.e. Chrome, Chromium, Palemoon, Waterfox, Firefox, Opera etc.. have the facility to change these associations to the aforementioned browser.
As it only mentions IE and Edge, no others.Windows - commercial by definition and now function...-
b
AskWoody_MVPApril 18, 2019 at 2:58 pm #549892My understanding is that Firefox, Palemoon, Waterfox may be less than ideal because Firefox can’t actually open .mht/.mhtml files (as Mozilla Archive Format extension went away), so will offer to open them in IE (defeating the purpose).
I believe Chrome, Chromium, Opera would be fine. (I’ve associated Chromium Edge Dev, which can open .mht/.mhtml files.)
Others have associated with Word, which can open .mht/.mhtml files (Word 2003 or later).
But for anyone without a special use for MHT files, Notepad.exe is probably good enough.
1 user thanked author for this post.
-
mn–
AskWoody LoungerApril 24, 2019 at 1:22 am #888281I note that Chrome doesn’t seem to register itself as a handler for these normally but some other Chromium-derived browsers do.
However… it’d seem that if you happen to have preview pane on, it’ll render these with IE for that anyway regardless of the association? Not sure about thumbnail generation, didn’t get a thumbnail for my quick test .mhtml but…
-
anonymous
GuestViewing 5 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Outdated Laptop
by
jdamkeene
35 minutes ago -
Updating Keepass2Android
by
CBFPD-Chief115
2 hours, 56 minutes ago -
Another big Microsoft layoff
by
Charlie
2 hours, 36 minutes ago -
PowerShell to detect NPU – Testers Needed
by
RetiredGeek
2 hours, 25 minutes ago -
May 2025 updates are out
by
Susan Bradley
3 hours, 1 minute ago -
Windows 11 Insider Preview build 26200.5600 released to DEV
by
joep517
8 hours, 40 minutes ago -
Windows 11 Insider Preview build 26120.3964 (24H2) released to BETA
by
joep517
8 hours, 42 minutes ago -
Drivers suggested via Windows Update
by
Tex265
8 hours, 32 minutes ago -
Thunderbird release notes for 128 esr have disappeared
by
EricB
6 hours, 17 minutes ago -
CISA mutes own website, shifts routine cyber alerts to X, RSS, email
by
Nibbled To Death By Ducks
15 hours, 32 minutes ago -
Apple releases 18.5
by
Susan Bradley
9 hours, 57 minutes ago -
Fedora Linux 40 will go end of life for updates and support on 2025-05-13.
by
Alex5723
16 hours, 58 minutes ago -
How a new type of AI is helping police skirt facial recognition bans
by
Alex5723
17 hours, 36 minutes ago -
Windows 7 ISO /Windows 10 ISO
by
ECWS
52 minutes ago -
No HP software folders
by
fpefpe
1 day, 1 hour ago -
Which antivirus apps and VPNs are the most secure in 2025?
by
B. Livingston
14 minutes ago -
Stay connected anywhere
by
Peter Deegan
1 day, 6 hours ago -
Copilot, under the table
by
Will Fastie
21 hours, 53 minutes ago -
The Windows experience
by
Will Fastie
1 day, 12 hours ago -
A tale of two operating systems
by
Susan Bradley
1 day, 3 hours ago -
Microsoft : Resolving Blue Screen errors in Windows
by
Alex5723
1 day, 18 hours ago -
Where’s the cache today?
by
Up2you2
2 days, 9 hours ago -
Ascension says recent data breach affects over 430,000 patients
by
Nibbled To Death By Ducks
2 days, 2 hours ago -
Nintendo Switch 2 has a remote killing switch
by
Alex5723
1 day, 2 hours ago -
Blocking Search (on task bar) from going to web
by
HenryW
4 hours, 54 minutes ago -
Windows 10: Microsoft 365 Apps will be supported up to Oct. 10 2028
by
Alex5723
3 days, 2 hours ago -
Add or Remove “Ask Copilot” Context Menu in Windows 11 and 10
by
Alex5723
3 days, 2 hours ago -
regarding april update and may update
by
heybengbeng
3 days, 4 hours ago -
MS Passkey
by
pmruzicka
2 days, 6 hours ago -
Can’t make Opera my default browser
by
bmeacham
3 days, 12 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.