Malformed .MHT File in Internet Explorer May Lead To File Theft
As Microsoft is gearing up with a new version of Microsoft Edge based-on Chromium engine, Internet Explorer, its ugly step-mother remains as part of Windows 10, and it is dragging its vulnerability towards Redmond’s latest operating system. The Proof-Of-Concept code has been released to demonstrate the XML eXternal Entity flaw in Internet Explorer 11, which Microsoft refused to fix for an undisclosed reason. This is a huge departure to Microsoft’s earlier commitment that the software giant will continue to patch Internet Explorer 11 which is bundled on all versions of Windows.
Internet Explorer is used for companies with Intranet systems still using ActiveX control, a legacy technology designed to deliver dynamic content to a webpage. However, such high interactivity comes with a huge setback, as malware from the early 2000s were based-on ActiveX technology. As Internet Explorer has almost the same market share as Mozilla Firefox today, users are advised to change the association of .mht files to notepad or some other text editor instead of Internet Explorer. This will cancel the possibility of automatically open .mht files in Internet Explorer.
“We determined that a fix for this issue will be considered in a future version of this product or service. At this time, we will not be providing ongoing updates of the status of the fix for this issue, and we have closed this case,” said a Microsoft representative in response to the issue.
Kevin Jones951 Posts
Kevin Jones, Ph.D., is a research associate and a Cyber Security Author with experience in Penetration Testing, Vulnerability Assessments, Monitoring solutions, Surveillance and Offensive technologies etc. Currently, he is a freelance writer on latest security news and other happenings. He has authored numerous articles and exploits which can be found on popular sites like hackercombat.com and others.