Internet Explorer’s legacy WebBrowser control can still be abused to turn a single user click into full remote code execution (RCE) on Windows systems, even though the browser is officially retired. PT Security observed that by exploiting IE’s zone model, Mark of the Web (MOTW) handling, and powerful COM/ActiveX components, attackers can transform seemingly harmless user interactions into code execution on the host. The core problem is that IE’s mshtml engine and WebBrowser control are still embedded in many desktop applications, especially older VB, .NET, and C/C++ tools with local web interfaces on http://localhost. These apps often lack robust HTML and JavaScript sanitization, making XSS a realistic starting...
Read the full article at the source.
Comments (0)
No comments yet. Be the first to comment!