# Internet Explorer WebBrowser Control Attack Chain — Two-Click RCE via Zone/MOTW Bypass and ActiveX COM (Positive Technologies)

> Positive Technologies documented a multi-stage attack chain that weaponizes Internet Explorer's legacy WebBrowser control (the mshtml engine still embedded in many VB/.NET/C/C++ desktop apps) to convert ordinary user clicks into remote code execution on Windows. The chain pivots from localhost XSS through IE's zone model and Mark-of-the-Web (MOTW) handling, uses Microsoft Edge to drop an un-tagged HTML payload, then instantiates high-risk COM/ActiveX objects such as WScript.Shell to achieve a 'two-click RCE'.

- **Published:** 2026-06-08T00:00:00Z
- **Last reviewed:** 2026-06-08T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0715
- **ID:** TL-2026-0715
- **Severity:** HIGH
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 13 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Positive Technologies (PT Security) research details how the deprecated Internet Explorer WebBrowser control — which remains embedded inside numerous legacy desktop applications written in Visual Basic, .NET, and C/C++ that expose local web user interfaces over http://localhost — can be chained into a reliable remote code execution primitive on modern Windows hosts. Although Microsoft retired the standalone Internet Explorer browser, the underlying mshtml rendering engine and its WebBrowser ActiveX control survive inside third-party software, carrying forward IE's legacy zone model and security weaknesses.

The chain begins with cross-site scripting against a localhost web UI. Because these embedded interfaces frequently lack robust HTML/JavaScript sanitization, an attacker who can reach the local web server (for example via a malicious page that pivots to localhost, or via stored/reflected XSS in the local app) gains JavaScript execution in the localhost zone. IE assigns the localhost and local-file zones special, elevated treatment relative to the Internet zone.

From there the attacker performs origin/zone escalation. A timing flaw in IE's window and dialog handling historically allowed JavaScript running under localhost to open local HTML files without the usual security prompts, converting remote-origin script into a local-origin script that executes with reduced restrictions. To obtain a controllable local file with scripting enabled and no Mark-of-the-Web, the chain recruits Microsoft Edge: the localhost script opens an Edge window pointed at an attacker URL, and Edge downloads an attacker-supplied HTML document into the Downloads directory WITHOUT applying a Mark-of-the-Web (Zone.Identifier) tag. The IE WebBrowser control is then redirected from localhost to that freshly downloaded file, turning a remote payload into a trusted-looking local HTML document with active scripting and no MOTW enforcement.

With a local, un-marked, script-enabled page rendered inside the WebBrowser control, the attacker instantiates high-risk ActiveX/COM automation objects — most notably WScript.Shell — which expose arbitrary command execution. The user receives an ActiveX security warning; approving it (a single 'Yes' click) yields execution of arbitrary commands, demonstrated with benign payloads like calc.exe but trivially repurposed to drop and run malware. Combined with the earlier Edge download click, the net result is a 'two-click RCE'.

The research also describes an auxiliary clickjacking vector that abuses Windows Explorer folder views and ZIP browsing surfaces. A tiny, cursor-following iframe hosting a folder or ZIP view is overlaid under the pointer so that a user's clicks are redirected into double-clicking a malicious file inside the view. Files reached this way frequently carry weak or missing MOTW enforcement, allowing execution without the expected protected-view or SmartScreen friction.

No CVE has been assigned to the overall chain; Microsoft has, over time, fixed individual pivots (notably the direct 'open local file from localhost script' timing behavior) after demonstration, but the systemic risk persists wherever the embedded WebBrowser control is still shipped. The threat is a technique/PoC-grade disclosure with broad legacy-software exposure rather than a single patchable vulnerability.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1566.002 Phishing: Spearphishing Link
- T1189 Drive-by Compromise
- T1204.002 User Execution: Malicious File
- T1059.005 Command and Scripting Interpreter: Visual Basic
- T1059.003 Command and Scripting Interpreter: Windows Command Shell
- T1559.001 Inter-Process Communication: Component Object Model
- T1553.005 Subvert Trust Controls: Mark-of-the-Web Bypass
- T1218.005 System Binary Proxy Execution: Mshta
- T1036.005 Match Legitimate Resource Name or Location
- T1548 Abuse Elevation Control Mechanism
- T1056.002 GUI Input Capture

## Sources

- [Internet Explorer WebBrowser Control Attack Chain Turns Clicks Into RCE](https://cybersecuritynews.com/internet-explorer-webbrowser-attack/)
- [Mark of the Web (Internet Explorer) — Microsoft Learn](https://learn.microsoft.com/en-us/previous-versions/windows/internet-explorer/ie-developer/compatibility/ms537628(v=vs.85))
- [Out-of-date ActiveX control blocking (Internet Explorer 11) — Microsoft Learn](https://learn.microsoft.com/en-us/previous-versions/windows/internet-explorer/ie-it-pro/internet-explorer-11/ie11-deploy-guide/out-of-date-activex-control-blocking)
- [Windows MSHTML zero-day defenses bypassed as new info emerges — BleepingComputer](https://www.bleepingcomputer.com/news/microsoft/windows-mshtml-zero-day-defenses-bypassed-as-new-info-emerges/)
- [Windows 10 RCE: The exploit is in the link — Positive Security](https://positive.security/blog/ms-officecmd-rce)
- [MITRE ATT&CK T1059.005 — Visual Basic / Windows Script Host](https://attack.mitre.org/techniques/T1059/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0715
