Threat reportVulnerabilityTL-2026-1549
CVE-2026-20841: Command Injection in Windows Notepad Markdown Link Handling Enables Arbitrary Code Execution
CVE-2026-20841 (TL-2026-1549) is a high-severity software vulnerability scored CVSS 7.8, first published 2026-02-19. It has no confirmed attribution, affects Microsoft Windows Notepad (Microsoft Store / modern app), references 1 CVE (CVE-2026-20841), maps to 18 MITRE ATT&CK techniques (T1036.005, T1059, T1071.001), and is covered by 9 detection rules and 20 indicators of compromise.
- CVSS
- 7.8/10High
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 18MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 20Indicators of compromise
Key facts for TL-2026-1549
- Threat ID
- TL-2026-1549
- Severity
- HIGH
- CVSS
- 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- all sectors using windows 11, enterprise, government administration, education, health, finance, technology
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 20
Malware and tooling in CVE-2026-20841
Malware and tooling: Generic protocol-handler dropper (delivery-stage, no specific malware family attributed), 404godd/CVE-2026-20841-PoC, BTtea/CVE-2026-20841-PoC, dogukankurnaz/CVE-2026-20841-PoC, hackfaiz/CVE-2026-20841-PoC
How CVE-2026-20841 works
Windows Notepad's Markdown rendering feature insufficiently validates link URIs before passing them to the system shell (ShellExecuteExW), allowing attackers to craft malicious .md files whose embedded links invoke dangerous protocol handlers such as file:// and ms-appinstaller:// to execute arbitrary local or remote payloads when a victim clicks (or Ctrl-clicks) the rendered link. Five verified public PoC exploits exist on GitHub; Microsoft patched the flaw in the February 10, 2026 Patch Tuesday release (build 11.2510).
CVE-2026-20841 is a local command-injection vulnerability (CWE-77: Improper Neutralization of Special Elements used in a Command) in the modern Windows Notepad application (Microsoft Store package), which gained Markdown rendering and editing support in 2025. When Notepad detects a file with a .md extension via fixed string comparison, it tokenizes the file content for Markdown rendering, including hyperlink syntax such as [text](target). The link-click handler (identified in ZDI's binary analysis as sub_140170F60 in Notepad.exe) passes the link target directly to the Windows shell for execution without adequately filtering or validating the URI scheme. This allows an attacker to embed links using non-http(s) protocol handlers -- most notably file:// (direct local file execution) and ms-appinstaller:// (Windows App Installer protocol, historically abused as an initial-access vector by ransomware affiliates such as Storm-0569/BATLOADER) -- inside a seemingly benign Markdown text file. Because Markdown files are widely perceived by end users as inert plain text, victims exhibit low suspicion when opening .md attachments, and Notepad's rendering silently converts the file into an interactive execution surface the moment a link is clicked or Ctrl-clicked. Microsoft's official advisory states: "An attacker could trick a user into clicking a malicious link inside a Markdown file opened in Notepad, causing the application to launch unverified protocols that load and execute remote files." Exploitation requires user interaction (opening the crafted .md file and clicking the link) and executes in the context of the logged-on user -- no privilege escalation or sandbox escape is required for the initial code-execution primitive, though follow-on payloads (e.g., an MSIX package delivered via ms-appinstaller://) can themselves carry further capability. The vulnerability affects the Microsoft Store ("modern"/UWP-packaged) build of Notepad versions 11.0.0 through 11.2509; it does not affect the legacy Win32 notepad.exe, which lacks Markdown rendering. Microsoft remediated the issue in the February 10, 2026 update (build 11.2510) by adding an interstitial "This link may be unsafe" warning for non-http/https link schemes -- a warn-and-allow mitigation rather than an outright block, meaning a sufficiently social-engineered victim can still click through and trigger execution even on patched builds. The flaw was discovered and reported by independent researchers Cristian Papa and Alasdair Gorniak (credited by Delta Obscura / community writeups), with additional bug-hunting credit to a researcher known as "Chen"; technical root-cause analysis and the detection regexes referenced in this report were published by Nikolai Skliarenko and Yazhi Wang of Trend Micro's Zero Day Initiative (ZDI) research team. Multiple independent proof-of-concept repositories were published to GitHub within days of disclosure (BTtea, dogukankurnaz, 404godd, hackfaiz, and others), demonstrating both remote-payload-installation (via ms-appinstaller://) and local-executable-invocation (via file://) attack vectors, keeping exploit maturity and reproducibility high even though no in-the-wild active exploitation had been publicly confirmed as of the disclosure window.
MITRE ATT&CK techniques used in TL-2026-1549
Defense Evasion
T1036.005 Match Legitimate Resource Name or Location; T1127 Trusted Developer Utilities Proxy Execution; T1140 Deobfuscate/Decode Files or Information; T1218.007 Msiexec
Execution
T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution; T1204 User Execution; T1204.001 Malicious Link; T1204.002 Malicious File
Command and Control
T1071.001 Web Protocols; T1105 Ingress Tool Transfer
Impact
T1499 Endpoint Denial of Service
Persistence
T1546.003 Windows Management Instrumentation Event Subscription
Initial Access
T1566 Phishing; T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link
Resource Development
Affected products and versions in CVE-2026-20841
- Microsoft — Windows Notepad (Microsoft Store / modern app)
Vulnerable versions: 11.0.0; 11.2508; 11.2509
Fixed in: 11.2510 and later
Remediation for CVE-2026-20841
Patches
- Windows Notepad (Microsoft Store) build 11.2510 -- released February 10, 2026 Patch Tuesday cycle; adds 'This link may be unsafe' interstitial warning for non-http/https link schemes
Immediate actions
- Update Windows Notepad (Microsoft Store app) to build 11.2510 or later via Microsoft Store, enabling automatic app updates if not already enabled
- Educate users that .md/Markdown files are not inherently safe and that clicking embedded links -- especially non-http(s) links -- can trigger code execution
- Block or alert on file downloads/emails delivering .md attachments from untrusted or external senders at the email/web gateway
- Restrict or monitor invocation of the ms-appinstaller:// protocol handler at the endpoint level given its history of abuse as an initial-access vector
Workarounds
- Do not click or Ctrl+click hyperlinks rendered inside .md files opened in Notepad from untrusted sources prior to updating
- Open untrusted Markdown files in a plain-text viewer or sandboxed VM instead of the modern Notepad app
- Disable or restrict the ms-appinstaller:// and other non-essential custom URI protocol handlers via Group Policy / registry where feasible
Longer-term hardening
- Deploy EDR rules to flag Notepad.exe (modern/Store variant) spawning child processes or invoking ShellExecute on non-http(s) URI schemes
- Apply application control (WDAC/AppLocker) policies restricting execution of MSIX/AppX packages from non-trusted publishers via App Installer
- Implement network/endpoint detection for outbound App Installer (ms-appinstaller) protocol invocations correlated with recent Markdown file opens
- Maintain a patch-compliance baseline for Microsoft Store-distributed applications, not just traditional Win32 software, given they can silently reintroduce attack surface
CVEs associated with CVE-2026-20841
CVE-2026-20841
Weaknesses (CWE) in CVE-2026-20841
Timeline of CVE-2026-20841
- Microsoft adds Markdown rendering and editing support to the modern Windows Notepad app, introducing the underlying attack surface later exploited by CVE-2026-20841.
- Vulnerability privately reported to Microsoft by researchers Cristian Papa and Alasdair Gorniak (credited alongside researcher 'Chen') via responsible disclosure.
- Microsoft ships the fix for CVE-2026-20841 in Windows Notepad build 11.2510 as part of the February 2026 Patch Tuesday cycle, adding an 'unsafe link' warning for non-http/https URIs.
- SOC Prime publishes coverage of CVE-2026-20841, confirming CVSS 8.8/Important classification and detailing the fixed build.
- Help Net Security publishes analysis of the vulnerability, noting Microsoft's mitigation approach and researcher credits; story trends on Hacker News.
- ThreatLocker publishes blog analysis explaining the Markdown risk and providing guidance for endpoint protection customers.
- Mallory.ai vulnerability intelligence platform publishes independent CVSS v3.1 scoring (7.8) and EPSS scoring (11.7%, 96th percentile) along with CWE-77 classification.
- Zero Day Initiative (ZDI) publishes deep technical root-cause analysis by Nikolai Skliarenko and Yazhi Wang, including the vulnerable function (sub_140170F60) and detection regex patterns for file:// and ms-appinstaller:// abuse.
- Multiple independent proof-of-concept repositories (BTtea/CVE-2026-20841-PoC, dogukankurnaz/CVE-2026-20841-PoC) published to GitHub demonstrating remote-payload and local-file execution vectors.
- Additional PoC repositories (404godd/CVE-2026-20841-PoC, hackfaiz/CVE-2026-20841-PoC) published, further increasing exploit reproducibility; Penligent publishes multi-part hacking-labs technical writeup series.
Sources cited for CVE-2026-20841
- Zero Day Initiative — CVE-2026-20841: Arbitrary Code Execution in the Windows Notepad
- Windows Notepad Markdown feature opens door to RCE (CVE-2026-20841) - Help Net Security
- CVE-2026-20841: Windows Notepad RCE Fixed in Microsoft's February Patch Tuesday Release
- CVE-2026-20841 - Security Update Guide - Microsoft - Windows Notepad App Remote Code Execution Vulnerability
- Windows Notepad vulnerability: Markdown risk explained | ThreatLocker Blog
- Remote Code Execution in Windows Notepad App via Markdown Link Handling (CVE-2026-20841) | Mallory
- Windows Notepad CVE-2026-20841 PoC: When Markdown Links Turn a Text Editor Into an Execution Boundary
- CVE-2026-20841 — When Markdown in Windows Notepad Becomes an Execution Path
- NVD - CVE-2026-20841
- BTtea/CVE-2026-20841-PoC
- dogukankurnaz/CVE-2026-20841-PoC
- 404godd/CVE-2026-20841-PoC
- hackfaiz/CVE-2026-20841-PoC
- Hacker News discussion: CVE-2026-20841
Detection coverage for TL-2026-1549
As of 2026-02-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1549 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.