I’ve been slammed for the past few days, and haven’t kept you folks apprised of the latest Internet Explorer 0day. It depends on you opening an infect
[See the full post at: That Internet Explorer XXE zero day poking through to Edge]
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
That Internet Explorer XXE zero day poking through to Edge
Home » Forums » Newsletter and Homepage topics » That Internet Explorer XXE zero day poking through to Edge
- This topic has 16 replies, 9 voices, and was last updated 6 years, 1 month ago.
Tags: 0patch Edge Internet Explorer XXE 0day
AuthorTopicViewing 5 reply threadsAuthorReplies-
anonymous
Guest -
MikeMc
AskWoody LoungerApril 18, 2019 at 8:41 am #541656 -
GoneToPlaid
AskWoody LoungerApril 18, 2019 at 9:46 am #542988 -
GoneToPlaid
AskWoody Lounger -
warrenrumak
AskWoody Lounger -
b
AskWoody_MVPApril 18, 2019 at 12:12 pm #546381 -
warrenrumak
AskWoody LoungerApril 18, 2019 at 2:53 pm #549782You still had to choose to download the file from an unknown source, and you had to choose to open it.
If an attacker can convince you to do that, they probably could convince you to download and run an executable. Or a Powershell script. Or a batch file. Or a vbs file. Or a malicious RAR file that targets WinRAR.
Also, one would presume that most of the major AV vendors already have a heuristics check in place that’ll detect this particular attack. Inspecting and flagging dodgy MHT files something they’ve been doing for almost 20 years…. it’s hardly new ground.
-
-
-
-
b
AskWoody_MVPApril 18, 2019 at 10:47 am #544292A few observations:
1. Not using IE doesn’t help, as long as it’s enabled and associated with .mht and/or .mhtml files.
Fred Langa says today; “Even if you never use IE, never click on it, or never call it up in any way, it’s there, and this new exploit can make use of it. In fact, if you use any version of Windows, you almost surely have IE on your PC.” Microsoft Windows users take note
2. The exploit can only read and transmit a named file from a known location. The proof of concept used c:\windows\system.ini which is probably identical on billions of computers. Which file on my computer would you like to read which could subject me to some form of future danger or even privacy invasion?
3. The original author said the exploit proof of concept had also been tested on Windows 7 and Server 2012 R2, but perhaps that was with an HTM file previously downloaded via Edge on Windows 10?
1 user thanked author for this post.
-
woody
Manager -
GoneToPlaid
AskWoody LoungerApril 18, 2019 at 11:29 am #545362
-
-
Microfix
AskWoody MVPApril 18, 2019 at 1:07 pm #547642Are these file associations safe to use in a different browser as defaults?
i.e. Chrome, Chromium, Palemoon, Waterfox, Firefox, Opera etc.. have the facility to change these associations to the aforementioned browser.
As it only mentions IE and Edge, no others.Windows - commercial by definition and now function... -
b
AskWoody_MVPApril 18, 2019 at 2:58 pm #549892My understanding is that Firefox, Palemoon, Waterfox may be less than ideal because Firefox can’t actually open .mht/.mhtml files (as Mozilla Archive Format extension went away), so will offer to open them in IE (defeating the purpose).
I believe Chrome, Chromium, Opera would be fine. (I’ve associated Chromium Edge Dev, which can open .mht/.mhtml files.)
Others have associated with Word, which can open .mht/.mhtml files (Word 2003 or later).
But for anyone without a special use for MHT files, Notepad.exe is probably good enough.
1 user thanked author for this post.
-
mn–
AskWoody LoungerApril 24, 2019 at 1:22 am #888281I note that Chrome doesn’t seem to register itself as a handler for these normally but some other Chromium-derived browsers do.
However… it’d seem that if you happen to have preview pane on, it’ll render these with IE for that anyway regardless of the association? Not sure about thumbnail generation, didn’t get a thumbnail for my quick test .mhtml but…
-
-
-
anonymous
Guest
Viewing 5 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Microsoft : Edge is better than Chrome
by
Alex5723
2 hours, 56 minutes ago -
The EU launched DNS4EU
by
Alex5723
8 hours, 30 minutes ago -
Cell Phone vs. Traditional Touchtone Phone over POTS
by
280park
6 hours, 35 minutes ago -
Lost access to all my networked drives (shares) listed in My Computer
by
lwerman
13 hours, 56 minutes ago -
Set default size for pasted photo to word
by
Cyn
19 hours, 58 minutes ago -
Dedoimedo tries 24H2…
by
Cybertooth
8 hours, 4 minutes ago -
Windows 11 Insider Preview build 27871 released to Canary
by
joep517
1 day, 18 hours ago -
Windows 11 ad from Campaign Manager in Windows 10
by
Jim McKenna
1 day, 16 hours ago -
Small desktops
by
Susan Bradley
9 hours, 37 minutes ago -
Totally disable Bitlocker
by
CWBillow
12 hours, 30 minutes ago -
Phishers extract Millions from HMRC accounts..
by
Microfix
1 day, 16 hours ago -
Windows 10 22H2 Update today (5 June) says up-to-date but last was 2025-04
by
Alan_uk
2 days, 22 hours ago -
Thoughts on Malwarebytes Scam Guard for Mobile?
by
opti1
17 hours, 39 minutes ago -
Mystical Desktop
by
CWBillow
3 days, 2 hours ago -
Meta and Yandex secretly tracked billions of Android users
by
Alex5723
2 days, 7 hours ago -
MS-DEFCON 2: Do you need that update?
by
Susan Bradley
23 hours, 26 minutes ago -
CD/DVD drive is no longer recognized
by
WSCape Sand
3 days, 17 hours ago -
Windows 11 24H2 Default Apps stuck on Edge and Adobe Photoshop
by
MikeBravo
3 days, 20 hours ago -
North Face and Cartier customer data stolen in cyber attacks
by
Alex5723
3 days, 18 hours ago -
What is wrong with simple approach?
by
WSSpoke36
1 day, 16 hours ago -
Microsoft-Backed Builder.ai Set for Bankruptcy After Cash Seized
by
Alex5723
4 days, 5 hours ago -
Location, location, location
by
Susan Bradley
2 days, 20 hours ago -
Cannot get a task to run a restore point
by
CWBillow
4 days, 7 hours ago -
Frustrating search behavior with Outlook
by
MrJimPhelps
3 days, 21 hours ago -
June 2025 Office non-Security Updates
by
PKCano
4 days, 17 hours ago -
Secure Boot Update Fails after KB5058405 Installed
by
SteveIT
6 hours, 45 minutes ago -
Firefox Red Panda Fun Stuff
by
Lars220
4 days, 17 hours ago -
How start headers and page numbers on page 3?
by
Davidhs
5 days, 4 hours ago -
Attack on LexisNexis Risk Solutions exposes data on 300k +
by
Nibbled To Death By Ducks
4 days, 6 hours ago -
Windows 11 Insider Preview build 26200.5622 released to DEV
by
joep517
5 days, 12 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.