logo

Weaponizing .SettingContent-ms Extensions for Code Execution

ID: 94f42555-9fa9-5d70-8ede-b2b239866413

STIX ID: report--94f42555-9fa9-5d70-8ede-b2b239866413

Feed Name: TrustedSec blog

Threat Score
75/100

Date Published: 2025-03-24

Date Updated: 2026-05-01

...
...

This report documents the weaponization of .SettingContent-ms files to achieve remote code execution on Windows systems by abusing the DeepLink element to call trusted binaries (e.g., mshta.exe) that fetch and execute malicious HTA payloads. The author demonstrates PoCs using obfuscated PowerShell/meterpreter payloads, details a 517-character DeepLink limit, provides an automation script (auto_SettingContent-ms), reports successful red-team use, and recommends mitigations such as blocking the file type at the perimeter or changing file associations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.