Microsoft Windows MSHTML Platform Spoofing Vulnerability

Strike ID:
E24-iy8w1
CVSS:
7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
False Positive:
f
Variants:
2
Year:
2024

Description

This strike exploits a spoofing vulnerability in the Windows MSHTML platform. The vulnerability arises from improper validation of link addresses in Internet Shortcut Files (".url" extension). When a specially crafted ".url" file is opened, the URL is incorrectly handled if it starts with a protocol prefix like "mhtml:". This improper handling can result in requests being made to an attacker-controlled location. The attacker can also control the icon and appearance of the ".url" file, making it misleading to users. A remote attacker can exploit this vulnerability by tricking a target user into opening a crafted ".url" file, which could lead to spoofing attacks or NTLM relay attacks, potentially exposing authentication details.

CVE

References