It’s pretty easy, if you know the tricks. Step-by-step details coming in Computerworld.
[See the full post at: To block the latest zero day, instead of removing Internet Explorer, just short-circuit access to MHT files]
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
To block the latest zero day, instead of removing Internet Explorer, just short-circuit access to MHT files
Home » Forums » Newsletter and Homepage topics » To block the latest zero day, instead of removing Internet Explorer, just short-circuit access to MHT files
- This topic has 50 replies, 23 voices, and was last updated 5 years, 10 months ago.
AuthorTopicViewing 27 reply threadsAuthorReplies-
anonymous
GuestApril 18, 2019 at 12:09 pm #546232You could be smart and just 0-Patch it. It’s already been patched for 3 days now:
https://blog.0patch.com/2019/04/microsoft-edge-uses-secret-trick-and.html
-
woody
ManagerApril 18, 2019 at 1:57 pm #5485560patch is great but I just can’t bring myself to recommend (or support) a 3rd-party fix to Windows binaries. See this:
The 0patch company has a quick patch that you can apply, free, if you’re concerned about getting burned. I’m not going to link to it — I don’t want to take responsibility for 3rd-party patches to Windows — but you can find it quite easily if you’re really interested. That said, 0patch is highly regarded, and has made many useful hotfixes for Windows.
-
anonymous
GuestApril 18, 2019 at 11:36 pm #565285The 0patch blog states that the patch is only available for fully updated windows versions. Since we are still at MS-DEFCON 2, most of us won’t be fully updated yet.
I am on 1809 and am still waiting for the go-ahead. I have 0patch installed, the patches are shown as available in the installed patch list, but not amongst the patchable modules. So I would need to update to the latest Quality Update for it to work.
-
anonymous
Guest
-
-
anonymous
GuestApril 18, 2019 at 12:40 pm #546857-
anonymous
Guest
davinci953
AskWoody PlusApril 18, 2019 at 1:03 pm #547539<snip>
What about mhtml extension – is it also vulnerable, should it also be changed?
I was curious about that extension as well. For now I just associated the file type with my default browser instead of IE on my Windows 7 system. In reading the article on 0patch, it appears that the exploit works on Windows 10 when using Edge but not Windows 7 with IE only. YMMV.
EstherD
AskWoody LoungerApril 18, 2019 at 1:18 pm #547864So this “workaround” for Win7 is fine for a single user machine. But what about machines configured with multiple users? I don’t want to, and in some cases cannot, log in and do the workaround for each user individually. Is there some way to configure these file associations system-wide in one fell swoop?
anonymous
GuestKarenS
AskWoody LoungerApril 18, 2019 at 1:36 pm #548196I don’t seem to have Notepad.exe on my Windows 7 home premium 32 bit laptop but I do see Microsoft Word at the top next to Internet Explorer when I click on “change program” is it okay to use that instead??
WAIT……when I click on the little arrow next to “other programs” I see Notepad……IS that what I am looking for??
Thanks!
anonymous
GuestApril 18, 2019 at 1:44 pm #548055I’ve delinked the MHT & MHTML file associations & handling from Internet Explorer on my Win 7 SP1. So when such files are clicked, there is a popup asking which program I wish to use to open the file.
That being said, if Windows Explorer’s preview pane is enabled, selecting a MHT/MHTML will result in its contents being displayed in the preview pane.
I assume Windows Explorer & its preview pane are intimately powered by (or entangled with) Internet Explorer — or at least that’s my impression from countless warnings to keep Internet Explorer patched, whether one explicitly uses it or not.
As such, can the zero-day MHT/MHTML security vulnerability be exploited via Windows Explorer’s preview pane — or even when a malicious MHT/MHTML file is merely selected in Windows Explorer with the preview pane disabled ? If yes, what is the remedy ?
anonymous
GuestApril 18, 2019 at 1:49 pm #548269Charlie
AskWoody PlusApril 18, 2019 at 2:29 pm #549301We are all assuming that MHT/MHTML files cannot do any damage when directed to be run with Notepad. Are we absolutely sure about that? I’d rather direct them to the Recycle Bin if that was possible.
Being 20 something in the 70's was far more fun than being 70 something in the insane 20's-
anonymous
Guest
seamonkey420
AskWoody LoungerApril 18, 2019 at 2:46 pm #549640i’ve tracked down a way to possibly programmatically set notepad.exe to open mht and mhtml files. outlined the assoc and ftype commands w/registry keys here:
https://seamonkey420x.blogspot.com/2019/04/programmatically-associating-mht-and.html
IE still shows in list of apps to open with the first time you open a mht or mhtml file but notepad is set as the default. 🙂
hope that helps others that need a fix for a fleet of workstations.
EstherD
AskWoody Lounger-
TaskForce141
AskWoody LoungerApril 19, 2019 at 12:25 am #567329You can disable or lockdown the MHTML protocol in Windows system-wide, using the workarounds in security bulletin MS11-026. MHT/MHTML has been a problem for years.
Disabling it requires deleting a registry key. Locking it down also requires the registry and prevents the launch of script in all zones within an MHTML document.
OscarCP
MemberApril 18, 2019 at 5:04 pm #552879According to davinci953: ” In reading the article on 0patch, it appears that the exploit works on Windows 10 when using Edge but not Windows 7 with IE only. YMMV. ”
Could this be true about Windows 7 with IE11? Reading other comments here, this does not seem to be the case, but I rather ask a question that looks to have an obvious answer, when something important, such as a 0-day vulnerability, is the relevant issue and I want to double-check the information I have about it.
You would be surprised how often I’ve had useful and not at all obvious answers this way.
Ex-Windows user (Win. 98, XP, 7); since mid-2017 using also macOS. Presently on Monterey 12.15 & sometimes running also Linux (Mint).
MacBook Pro circa mid-2015, 15" display, with 16GB 1600 GHz DDR3 RAM, 1 TB SSD, a Haswell architecture Intel CPU with 4 Cores and 8 Threads model i7-4870HQ @ 2.50GHz.
Intel Iris Pro GPU with Built-in Bus, VRAM 1.5 GB, Display 2880 x 1800 Retina, 24-Bit color.
macOS Monterey; browsers: Waterfox "Current", Vivaldi and (now and then) Chrome; security apps. Intego AVanonymous
Guestanonymous
GuestMyAussie
AskWoody LoungerApril 18, 2019 at 6:16 pm #555261Having followed the instructions my “MHT File” is now directed to notepad, etc.
Instructions were spot on! THANKS
Should this fix also be done for MHTML Document to be directed to Notepad?
Win 7 Home, X64, SP1, Group B
Edited for HTML. Please use Text tab for copy/paste.
1 user thanked author for this post.
KarenS
AskWoody Loungerdavinci953
AskWoody PlusApril 18, 2019 at 6:49 pm #556238According to davinci953: ” In reading the article on 0patch, it appears that the exploit works on Windows 10 when using Edge but not Windows 7 with IE only. YMMV. ” Could this be true about Windows 7 with IE11? Reading other comments here, this does not seem to be the case, but I rather ask a question that looks to have an obvious answer, when something important, such as a 0-day vulnerability, is the relevant issue and I want to double-check the information I have about it. You would be surprised how often I’ve had useful and not at all obvious answers this way.
Read the 0patch article that ‘anonymous’ links to above. That was my interpretation from the article. I guess the validity of the findings depends on how accurate their analysis is about the exploit. I still changed the file associations. Better safe than sorry until MS gets it sorted out.
-
OscarCP
MemberApril 18, 2019 at 7:19 pm #557377davinci953:
I have found a link in one of the several “anonymous” entries above ours, which might be the one you were referring to, and in the article there the interaction of Edge and IE11 was discussed, the bottom line, as I understand it, being that one might have a vulnerability if has both Edge and IE11 installed:
“See the irony here? An undocumented security feature used by Edge neutralized an existing, undoubtedly much more important feature (mark-of-the-web) in Internet Explorer.
This is clearly a significant security issue, especially since the attack can be further improved from what was originally demonstrated. We have found that:
- the malicious MHT file doesn’t have to be downloaded and manually opened by the user – just opening it directly from Edge can be made to work as well;
- the exploit can be enhanced so that it works more silently, and extracts many local files using a single MHT file.
On the upside, only Edge users are at risk. No other leading web browsers and email clients we’ve tested are using the undocumented security flag on the downloaded files, which effectively blocks the exploit. ”
I have Windows 7 Pro, x64 SP1, and these browsers: IE11, Chrome, FireFox and Waterfox. No Edge anywhere to be found, and that is how I intend to keep it until I breathe my last.
So I am thinking that the problem, if I understand correctly the excerpt of the article I’ve copied above, is for people that, for whatever arcane reason of theirs, have Edge in Windows 7. So: not for me.
Anybody here knows otherwise?
Also, davinci953 has had what might be a good idea: to associate MHT (and MHTML?) to the default browser, rather than to Notepad, assuming this default is not IE11 (if yours is, then make another browser your default one ASAP!.
Anybody here thinks that is not such a good idea?
Ex-Windows user (Win. 98, XP, 7); since mid-2017 using also macOS. Presently on Monterey 12.15 & sometimes running also Linux (Mint).
MacBook Pro circa mid-2015, 15" display, with 16GB 1600 GHz DDR3 RAM, 1 TB SSD, a Haswell architecture Intel CPU with 4 Cores and 8 Threads model i7-4870HQ @ 2.50GHz.
Intel Iris Pro GPU with Built-in Bus, VRAM 1.5 GB, Display 2880 x 1800 Retina, 24-Bit color.
macOS Monterey; browsers: Waterfox "Current", Vivaldi and (now and then) Chrome; security apps. Intego AV
gkarasik
AskWoody PlusApril 18, 2019 at 8:14 pm #559332I ran into a wrinkle: After changing the .MHT file association to Notepad, the next time I opened IE11 (Win7 Ent 32-bit), IE asked if I wanted to make IE my default browser. When I said Yes, the .MHT association was changed back to Internet Explorer. I then went to IE Options, Programs, and unchecked “Tell me if Internet Explorer is not the default option” and then reset the .MHT association to Notepad, after which starting IE no longer changed the association back to IE.
GaryK
anonymous
Guestanonymous
Guest-
gkarasik
AskWoody Plus
honx
AskWoody LoungerApril 19, 2019 at 3:01 am #573005thx for advice. on windows 7 i linked both .mht and .mhtml to notepad.exe, to be on the safe side. windows 8.1 notebook i won’t power on anymore until next defcon 3 or greater state here on askwoody. so i did nothing on 8.1 as i assume this 0day will be fixed once april ie patch is clear to install…
PC: Windows 7 Ultimate, 64bit, Group B
Notebook: Windows 8.1, 64bit, Group Bdavews
AskWoody LoungerApril 19, 2019 at 3:31 am #574070I use MHT extensively here for local archive purposes. I open them from PaleMoon with the MozArchiver extension which also works with Firefox. The original version of Opera opened them natively. It is not exclusively an IE format. I do not use IE, full stop, and the default on my machines to open MHT is PaleMoon.
Again we have Woody coming up with rash suggestions without knowing the full facts, just as he did with the WinRar ACE issue. I would normally support what he says but now I am not so sure.
-
Paul T
AskWoody MVP -
davews
AskWoody LoungerApril 20, 2019 at 1:14 am #609487It is a bit more involved than you suggest. Vulnerable files have to be downloaded via Edge and then opened in IE. It is actually an Edge vulnerability rather than MHT or IE. And rather bizzarely it seems if you have any other AV than Defender it will block it. I have not read the Wilders article in depth but maybe you could update your coverage on it.
CraigS26
AskWoody PlusApril 19, 2019 at 7:11 am #581139W10-1809 Up-To-Date …. Hoping Woody-PKC confirms need to do MHTML w/Notepad, too (I did), after the “New RTF files” exercises I found in Control Panel / Choose Default Apps by File Type that MHT showed Notepad BUT MHTML did NOT. …. I [ 1-Left Clk’d ] and Changed it to Notepad that was shown as an alt app.
The question on Bad Guys getting access thru Explorer Preview Pane needs an answer, too.
And, IF/When an MSoft – MHT/MHTML – FIX is offered, do we simply reverse the Open With and Re-Associate with IE?
W10 Pro 22H2 / Hm-Stdnt Ofce '16 C2R / Macrium Pd vX / GP=2 + FtrU=Semi-Annual + Feature Defer = 1 + QU = 0
-
GoneToPlaid
AskWoody LoungerApril 20, 2019 at 5:31 am #617438 -
mn–
AskWoody LoungerApril 24, 2019 at 5:25 am #900212Hm. Is there a reason to set the association back to IE even if this does get fixed?
And if so, for everyone or just some? I mean, we have those who associate it with a non-network-capable tool, then some who use other browsers, … (and I wouldn’t be very suprised if it turns out that other browsers may also have flaws regarding active content in there, but at least they might be different flaws so malware would have to be rebuilt to a different target… or maybe not as the languages involved are pretty standardized…)
I mean, we can still use manual file open, can’t we?
-
MyAussie
AskWoody Lounger
-
Northwest Rick
AskWoody LoungerNoel Carboni
AskWoody_MVPApril 20, 2019 at 12:10 pm #627273-
Noel Carboni
AskWoody_MVP -
DrBonzo
AskWoody PlusApril 21, 2019 at 1:34 pm #688727It seems to me that most discoverers of security holes are 1) trying to show off how smart they are and/or 2) trying to show how dumb the other software writers are. When the discoverer isn’t given what they consider proper recognition for their discovery they get offended and their retribution is to publish a proof of concept (or similar).
I’m no fan of Microsoft, but I suspect that they might know more about their software and potential security threats than independent discoverers of security holes.
1 user thanked author for this post.
OscarCP
MemberApril 21, 2019 at 2:11 pm #690346Not only I agree with Neil Carboni and DrBonzo, I am also very glad to see that someone here shares my long-held opinion that releasing publicly, for all to see, information on how one could exploit an OS vulnerability, whatever the excuse for doing it, is an appalling thing to do.
Ex-Windows user (Win. 98, XP, 7); since mid-2017 using also macOS. Presently on Monterey 12.15 & sometimes running also Linux (Mint).
MacBook Pro circa mid-2015, 15" display, with 16GB 1600 GHz DDR3 RAM, 1 TB SSD, a Haswell architecture Intel CPU with 4 Cores and 8 Threads model i7-4870HQ @ 2.50GHz.
Intel Iris Pro GPU with Built-in Bus, VRAM 1.5 GB, Display 2880 x 1800 Retina, 24-Bit color.
macOS Monterey; browsers: Waterfox "Current", Vivaldi and (now and then) Chrome; security apps. Intego AVPaul T
AskWoody MVPApril 22, 2019 at 1:08 am #726284The only way companies change their ways is in response to commercial pressure. Public disclosure of anything you think warrants change is an acceptable form of applying said pressure. In this case, notifying the company in advance is ethical behaviour, public disclosure is the next step.
cheers, Paul
1 user thanked author for this post.
-
OscarCP
MemberApril 23, 2019 at 11:42 am #846645Public disclosure that “there is this serious problem with this product that puts its users at risk of attacks by criminals, but the company that makes and sells it says they won’t do anything about it”, if true, it is a “public service”.
But saying the above and then adding, also in public: “and these are the details of how bad actors can exploit this problem” is not. That should be discussed communications between security experts, not splashed out for all to see, as it seems to have happened here.
Ex-Windows user (Win. 98, XP, 7); since mid-2017 using also macOS. Presently on Monterey 12.15 & sometimes running also Linux (Mint).
MacBook Pro circa mid-2015, 15" display, with 16GB 1600 GHz DDR3 RAM, 1 TB SSD, a Haswell architecture Intel CPU with 4 Cores and 8 Threads model i7-4870HQ @ 2.50GHz.
Intel Iris Pro GPU with Built-in Bus, VRAM 1.5 GB, Display 2880 x 1800 Retina, 24-Bit color.
macOS Monterey; browsers: Waterfox "Current", Vivaldi and (now and then) Chrome; security apps. Intego AV
anonymous
GuestApril 23, 2019 at 9:39 am #841603Don’t forget to cripple access to .js and .vbs files & many others as well. Just have them opened by default with notepad.
1 user thanked author for this post.
-
OscarCP
MemberApril 23, 2019 at 12:01 pm #847426Anonymous: Thanks for the heads up!
I have Webroot SecureAnywhere in a Windows 7 Pro PC and a macOS Mojave Mac, respectively. Unfortunately the article does not seem to apply to either. Perhaps it is relevant only to Windows 10. Or, if to Windows 7, to a different version from Professional, perhaps Enterprise?
If anyone here knows about how to implement this protection with SecureAnywhere for Win 7 or macOS (ex OS X), I would sincerely appreciate their giving some relevant details.
Ex-Windows user (Win. 98, XP, 7); since mid-2017 using also macOS. Presently on Monterey 12.15 & sometimes running also Linux (Mint).
MacBook Pro circa mid-2015, 15" display, with 16GB 1600 GHz DDR3 RAM, 1 TB SSD, a Haswell architecture Intel CPU with 4 Cores and 8 Threads model i7-4870HQ @ 2.50GHz.
Intel Iris Pro GPU with Built-in Bus, VRAM 1.5 GB, Display 2880 x 1800 Retina, 24-Bit color.
macOS Monterey; browsers: Waterfox "Current", Vivaldi and (now and then) Chrome; security apps. Intego AV -
phaolo
AskWoody Lounger -
The Surfing Pensioner
AskWoody Plus
-
Viewing 27 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Latest Firefox requires Password on start up
by
Gordski
56 minutes ago -
Resolved : AutoCAD 2022 might not open after updating to 24H2
by
Alex5723
4 hours, 10 minutes ago -
Missing api-ms-win-core-libraryloader-11-2-1.dll
by
IreneLinda
1 minute ago -
How Much Daylight have YOU Saved?
by
Nibbled To Death By Ducks
44 minutes ago -
A brief history of Windows Settings
by
Simon Bisson
2 hours, 38 minutes ago -
Thunderbolt is not just for monitors
by
Ben Myers
50 minutes ago -
Password Generators — Your first line of defense
by
Deanna McElveen
2 minutes ago -
AskWoody at the computer museum
by
Will Fastie
22 minutes ago -
Planning for the unexpected
by
Susan Bradley
1 hour, 20 minutes ago -
Which printer type is the better one to buy?
by
Bob99
5 hours, 55 minutes ago -
Upgrading the web server
by
Susan Bradley
4 hours, 20 minutes ago -
New Windows 11 24H2 Setup – Initial Win Update prevention settings?
by
Tex265
23 hours, 25 minutes ago -
Creating a Google account
by
DavidofIN
22 hours, 10 minutes ago -
Undocumented “backdoor” found in Bluetooth chip used by a billion devices
by
Alex5723
1 day, 4 hours ago -
Microsoft Considering AI Models to Replace OpenAI’s in Copilot
by
Alex5723
1 day, 15 hours ago -
AI *emergent misalignment*
by
Alex5723
1 day, 16 hours ago -
Windows 11 Disk Encryption/ Bitlocker/ Recovery Key
by
Tex265
52 minutes ago -
Trouble signing out and restarting
by
Tech Hiker
17 hours, 28 minutes ago -
Windows 7 MSE Manual Updating
by
Microfix
2 days, 1 hour ago -
Problem running LMC 22 flash drive
by
Charlie
1 day ago -
Outlook Email Problem
by
Lil88reb
1 day ago -
“Microsoft 365 Office All-in-One For Dummies, 3rd Edition FREE
by
Alex5723
1 day, 7 hours ago -
Cant use Office 2013 – Getting error message about Office 2013
by
SAAR
2 days ago -
Nearly 1 million Windows devices targeted in advanced “malvertising” spree
by
bbearren
2 days ago -
Windows 11 Insider Preview build 27808 released to Canary
by
joep517
3 days, 1 hour ago -
Windows 11 Insider Preview Build 22635.5025 (23H2) released to BETA
by
joep517
3 days, 1 hour ago -
Sysprep issue
by
Evit
3 days, 1 hour ago -
Android Security Bulletin—March 2025
by
Alex5723
3 days, 3 hours ago -
23h2: PIN TO START randomly available on right-click
by
dataman1701
3 days, 3 hours ago -
Microsoft Defender
by
agoldhammer
3 days, 9 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.