# CVE-2026-20841: Command Injection in Windows Notepad Markdown Link Handling Enables Arbitrary Code Execution

> Windows Notepad's Markdown rendering feature insufficiently validates link URIs before passing them to the system shell (ShellExecuteExW), allowing attackers to craft malicious .md files whose embedded links invoke dangerous protocol handlers such as file:// and ms-appinstaller:// to execute arbitrary local or remote payloads when a victim clicks (or Ctrl-clicks) the rendered link. Five verified public PoC exploits exist on GitHub; Microsoft patched the flaw in the February 10, 2026 Patch Tuesday release (build 11.2510).

- **Published:** 2026-02-19T00:00:00Z
- **Last reviewed:** 2026-02-19T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1549
- **ID:** TL-2026-1549
- **Severity:** HIGH (CVSS 7.8)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 20 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-20841

## Description

CVE-2026-20841 is a local command-injection vulnerability (CWE-77: Improper Neutralization of Special Elements used in a Command) in the modern Windows Notepad application (Microsoft Store package), which gained Markdown rendering and editing support in 2025. When Notepad detects a file with a .md extension via fixed string comparison, it tokenizes the file content for Markdown rendering, including hyperlink syntax such as [text](target). The link-click handler (identified in ZDI's binary analysis as sub_140170F60 in Notepad.exe) passes the link target directly to the Windows shell for execution without adequately filtering or validating the URI scheme. This allows an attacker to embed links using non-http(s) protocol handlers -- most notably file:// (direct local file execution) and ms-appinstaller:// (Windows App Installer protocol, historically abused as an initial-access vector by ransomware affiliates such as Storm-0569/BATLOADER) -- inside a seemingly benign Markdown text file. Because Markdown files are widely perceived by end users as inert plain text, victims exhibit low suspicion when opening .md attachments, and Notepad's rendering silently converts the file into an interactive execution surface the moment a link is clicked or Ctrl-clicked. Microsoft's official advisory states: "An attacker could trick a user into clicking a malicious link inside a Markdown file opened in Notepad, causing the application to launch unverified protocols that load and execute remote files." Exploitation requires user interaction (opening the crafted .md file and clicking the link) and executes in the context of the logged-on user -- no privilege escalation or sandbox escape is required for the initial code-execution primitive, though follow-on payloads (e.g., an MSIX package delivered via ms-appinstaller://) can themselves carry further capability. The vulnerability affects the Microsoft Store ("modern"/UWP-packaged) build of Notepad versions 11.0.0 through 11.2509; it does not affect the legacy Win32 notepad.exe, which lacks Markdown rendering. Microsoft remediated the issue in the February 10, 2026 update (build 11.2510) by adding an interstitial "This link may be unsafe" warning for non-http/https link schemes -- a warn-and-allow mitigation rather than an outright block, meaning a sufficiently social-engineered victim can still click through and trigger execution even on patched builds. The flaw was discovered and reported by independent researchers Cristian Papa and Alasdair Gorniak (credited by Delta Obscura / community writeups), with additional bug-hunting credit to a researcher known as "Chen"; technical root-cause analysis and the detection regexes referenced in this report were published by Nikolai Skliarenko and Yazhi Wang of Trend Micro's Zero Day Initiative (ZDI) research team. Multiple independent proof-of-concept repositories were published to GitHub within days of disclosure (BTtea, dogukankurnaz, 404godd, hackfaiz, and others), demonstrating both remote-payload-installation (via ms-appinstaller://) and local-executable-invocation (via file://) attack vectors, keeping exploit maturity and reproducibility high even though no in-the-wild active exploitation had been publicly confirmed as of the disclosure window.

## MITRE ATT&CK

- T1566 Phishing
- T1566.001 Spearphishing Attachment
- T1566.002 Spearphishing Link
- T1204 User Execution
- T1204.001 Malicious Link
- T1204.002 Malicious File
- T1059 Command and Scripting Interpreter
- T1203 Exploitation for Client Execution
- T1546.003 Windows Management Instrumentation Event Subscription
- T1218.007 Msiexec
- T1036.005 Match Legitimate Resource Name or Location
- T1140 Deobfuscate/Decode Files or Information
- T1127 Trusted Developer Utilities Proxy Execution
- T1071.001 Web Protocols
- T1105 Ingress Tool Transfer
- T1587.004 Exploits
- T1588.005 Exploits
- T1499 Endpoint Denial of Service

## Sources

- [Zero Day Initiative — CVE-2026-20841: Arbitrary Code Execution in the Windows Notepad](https://www.thezdi.com/blog/2026/2/19/cve-2026-20841-arbitrary-code-execution-in-the-windows-notepad)
- [Windows Notepad Markdown feature opens door to RCE (CVE-2026-20841) - Help Net Security](https://www.helpnetsecurity.com/2026/02/12/windows-notepad-markdown-feature-opens-door-to-rce-cve-2026-20841/)
- [CVE-2026-20841: Windows Notepad RCE Fixed in Microsoft's February Patch Tuesday Release](https://socprime.com/blog/cve-2026-20841-vulnerability/)
- [CVE-2026-20841 - Security Update Guide - Microsoft - Windows Notepad App Remote Code Execution Vulnerability](https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-20841)
- [Windows Notepad vulnerability: Markdown risk explained | ThreatLocker Blog](https://www.threatlocker.com/blog/windows-notepad-vulnerability-markdown-risk-explained)
- [Remote Code Execution in Windows Notepad App via Markdown Link Handling (CVE-2026-20841) | Mallory](https://www.mallory.ai/vulnerabilities/CVE-2026-20841)
- [Windows Notepad CVE-2026-20841 PoC: When Markdown Links Turn a Text Editor Into an Execution Boundary](https://www.penligent.ai/hackinglabs/windows-notepad-cve-2026-20841-poc-when-markdown-links-turn-a-text-editor-into-an-execution-boundary/)
- [CVE-2026-20841 — When Markdown in Windows Notepad Becomes an Execution Path](https://www.penligent.ai/hackinglabs/cve-2026-20841-when-markdown-in-windows-notepad-becomes-an-execution-path/)
- [NVD - CVE-2026-20841](https://nvd.nist.gov/vuln/detail/CVE-2026-20841)
- [BTtea/CVE-2026-20841-PoC](https://github.com/BTtea/CVE-2026-20841-PoC)
- [dogukankurnaz/CVE-2026-20841-PoC](https://github.com/dogukankurnaz/CVE-2026-20841-PoC)
- [404godd/CVE-2026-20841-PoC](https://github.com/404godd/CVE-2026-20841-PoC)
- [hackfaiz/CVE-2026-20841-PoC](https://github.com/hackfaiz/CVE-2026-20841-PoC)
- [Hacker News discussion: CVE-2026-20841](https://news.ycombinator.com/item?id=46971516)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1549
