Threat reportVulnerabilityTL-2026-0715

Internet Explorer WebBrowser Control Attack Chain — Two-Click RCE via Zone/MOTW Bypass and ActiveX COM (Positive Technologies)

highACTIVE

Internet Explorer WebBrowser Control Attack Chain (TL-2026-0715), also tracked as IE WebBrowser Control Two-Click RCE, is a high-severity software vulnerability, first published 2026-06-08. It has no confirmed attribution, affects Microsoft Internet Explorer WebBrowser Control (mshtml engine), maps to 12 MITRE ATT&CK techniques (T1036.005, T1056.002, T1059.003), and is covered by 9 detection rules and 13 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
12MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
13Indicators of compromise

Key facts for TL-2026-0715

Threat ID
TL-2026-0715
Also known as
IE WebBrowser Control Two-Click RCE, mshtml WebBrowser MOTW Bypass Chain
Severity
HIGH
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
technology, manufacturing, financial, healthcare, government
Target regions
Global
Detection rules
9
Indicators of compromise
13

Malware and tooling in Internet Explorer WebBrowser Control Attack Chain

Malware and tooling: ADODB.Stream, Internet Explorer WebBrowser Control (SHDocVw.WebBrowser), WScript.Shell

How Internet Explorer WebBrowser Control Attack Chain works

Positive Technologies documented a multi-stage attack chain that weaponizes Internet Explorer's legacy WebBrowser control (the mshtml engine still embedded in many VB/.NET/C/C++ desktop apps) to convert ordinary user clicks into remote code execution on Windows. The chain pivots from localhost XSS through IE's zone model and Mark-of-the-Web (MOTW) handling, uses Microsoft Edge to drop an un-tagged HTML payload, then instantiates high-risk COM/ActiveX objects such as WScript.Shell to achieve a 'two-click RCE'.

Positive Technologies (PT Security) research details how the deprecated Internet Explorer WebBrowser control — which remains embedded inside numerous legacy desktop applications written in Visual Basic, .NET, and C/C++ that expose local web user interfaces over http://localhost — can be chained into a reliable remote code execution primitive on modern Windows hosts. Although Microsoft retired the standalone Internet Explorer browser, the underlying mshtml rendering engine and its WebBrowser ActiveX control survive inside third-party software, carrying forward IE's legacy zone model and security weaknesses.

The chain begins with cross-site scripting against a localhost web UI. Because these embedded interfaces frequently lack robust HTML/JavaScript sanitization, an attacker who can reach the local web server (for example via a malicious page that pivots to localhost, or via stored/reflected XSS in the local app) gains JavaScript execution in the localhost zone. IE assigns the localhost and local-file zones special, elevated treatment relative to the Internet zone.

From there the attacker performs origin/zone escalation. A timing flaw in IE's window and dialog handling historically allowed JavaScript running under localhost to open local HTML files without the usual security prompts, converting remote-origin script into a local-origin script that executes with reduced restrictions. To obtain a controllable local file with scripting enabled and no Mark-of-the-Web, the chain recruits Microsoft Edge: the localhost script opens an Edge window pointed at an attacker URL, and Edge downloads an attacker-supplied HTML document into the Downloads directory WITHOUT applying a Mark-of-the-Web (Zone.Identifier) tag. The IE WebBrowser control is then redirected from localhost to that freshly downloaded file, turning a remote payload into a trusted-looking local HTML document with active scripting and no MOTW enforcement.

With a local, un-marked, script-enabled page rendered inside the WebBrowser control, the attacker instantiates high-risk ActiveX/COM automation objects — most notably WScript.Shell — which expose arbitrary command execution. The user receives an ActiveX security warning; approving it (a single 'Yes' click) yields execution of arbitrary commands, demonstrated with benign payloads like calc.exe but trivially repurposed to drop and run malware. Combined with the earlier Edge download click, the net result is a 'two-click RCE'.

The research also describes an auxiliary clickjacking vector that abuses Windows Explorer folder views and ZIP browsing surfaces. A tiny, cursor-following iframe hosting a folder or ZIP view is overlaid under the pointer so that a user's clicks are redirected into double-clicking a malicious file inside the view. Files reached this way frequently carry weak or missing MOTW enforcement, allowing execution without the expected protected-view or SmartScreen friction.

No CVE has been assigned to the overall chain; Microsoft has, over time, fixed individual pivots (notably the direct 'open local file from localhost script' timing behavior) after demonstration, but the systemic risk persists wherever the embedded WebBrowser control is still shipped. The threat is a technique/PoC-grade disclosure with broad legacy-software exposure rather than a single patchable vulnerability.

MITRE ATT&CK techniques used in TL-2026-0715

Defense Evasion

T1036.005 Match Legitimate Resource Name or Location; T1218.005 System Binary Proxy Execution: Mshta

Collection

T1056.002 GUI Input Capture

Execution

T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1059.005 Command and Scripting Interpreter: Visual Basic; T1204.002 User Execution: Malicious File; T1559.001 Inter-Process Communication: Component Object Model

Initial Access

T1189 Drive-by Compromise; T1190 Exploit Public-Facing Application; T1566.002 Phishing: Spearphishing Link

Privilege Escalation

T1548 Abuse Elevation Control Mechanism

defense-impairment

T1553.005 Subvert Trust Controls: Mark-of-the-Web Bypass

Affected products and versions in Internet Explorer WebBrowser Control Attack Chain

  • Microsoft — Internet Explorer WebBrowser Control (mshtml engine)
    Vulnerable versions: mshtml WebBrowser control as embedded in legacy desktop apps
    Fixed in: Individual pivots fixed via Windows cumulative updates; embedded-control risk persists
  • Microsoft — Microsoft Edge
    Vulnerable versions: Edge used as MOTW-stripping downloader in the chain
  • Third-party — Legacy VB/.NET/C/C++ desktop applications with localhost web UIs
    Vulnerable versions: Applications embedding the WebBrowser control without HTML/JS sanitization

Remediation for Internet Explorer WebBrowser Control Attack Chain

Patches

  • Apply current Windows cumulative updates; Microsoft has fixed individual pivots such as the localhost->local-file timing behavior over time

Immediate actions

  • Inventory desktop applications that embed the IE WebBrowser control or mshtml engine and expose localhost web UIs
  • Eliminate XSS in localhost/embedded web interfaces via strict output encoding and Content-Security-Policy
  • Approve no ActiveX security warnings from embedded application controls; train users that WScript.Shell prompts are unexpected

Workarounds

  • Set ActiveX kill bits / disable high-risk COM automation objects (WScript.Shell, ADODB.Stream) via policy
  • Enforce Mark-of-the-Web propagation and SmartScreen on downloaded files
  • Restrict outbound localhost access and isolate embedded web UIs from untrusted content

Longer-term hardening

  • Replace the IE WebBrowser control with modern sandboxed rendering controls (e.g., WebView2/Chromium)
  • Deploy EDR with behavioral detection for mshtml/WebBrowser-host processes spawning script interpreters or shells
  • Adopt application allowlisting to block command execution from WScript.Shell-initiated child processes

Weaknesses (CWE) in Internet Explorer WebBrowser Control Attack Chain

CWE-79, CWE-94, CWE-272, CWE-451, CWE-749

Timeline of Internet Explorer WebBrowser Control Attack Chain

  • Threadlinqs Intelligence begins tracking embedded-control exposure across legacy VB/.NET/C++ desktop software.
  • Researchers note Microsoft previously fixed the localhost->local-file timing pivot, but the embedded WebBrowser control risk persists in legacy apps.
  • Auxiliary clickjacking vector disclosed: cursor-following iframe over Explorer folder/ZIP views to force double-click execution of weakly-MOTW'd files.
  • Two-click RCE demonstrated via WScript.Shell launching benign payloads (e.g., calc.exe) inside the embedded WebBrowser control.
  • Full multi-stage chain documented: localhost XSS -> IE zone/origin escalation -> Edge MOTW-less download -> WebBrowser redirection -> ActiveX/COM command execution.
  • Positive Technologies (PT Security) publicly discloses the IE WebBrowser control attack chain; covered by Cyber Security News.

Sources cited for Internet Explorer WebBrowser Control Attack Chain

Detection coverage for TL-2026-0715

As of 2026-06-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0715 across Splunk SPL, Microsoft KQL and Sigma, covering 13 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
13 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats