FileFix Exploit Bypasses Mark-of-the-Web Protections via Windows Browser Flaw
ID: 3f1180e2-6f24-5a54-a1ae-7c96e8400b43
STIX ID: report--3f1180e2-6f24-5a54-a1ae-7c96e8400b43
Feed Name: Cyber Press
A flaw in Chrome and Edge causes saved HTML pages (e.g., "Webpage, Single File" or "Webpage, Complete") and Data URIs with MIME type text/html to be saved without the Windows Mark-of-the-Web (MOTW). Attackers can socially engineer users to rename such saved pages to a .hta extension so mshta.exe will execute embedded scripts without MOTW warnings, enabling execution of attacker-supplied commands. Mitigations include blocking or restricting mshta.exe and improving OS/browser tagging of downloaded HTML content.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
