Close Menu
Technotification
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    Technotification
    • Home
    • News
    • How To
    • Explained
    • Facts
    • Lists
    • Programming
    • Security
    • Gaming
    Technotification
    Home › News › Microsoft Edge File Permissions Conflicts with IE, Allows XXE Attacks

    Microsoft Edge File Permissions Conflicts with IE, Allows XXE Attacks

    By Subham KapisweJune 1, 2023
    Facebook Twitter Reddit LinkedIn
    microsoft edge

    Microsoft has recently released the first test build of Chromium-based Edge Browser and planning to release the stable version soon. One side, the company is striving to level up their web browser’s game, while on the other, Edge Browser and Internet Explorer are creating some serious security issues that could put the data of millions of Windows users at risk.

    Microsoft Edge File Permissions Conflicts could Allow XXE Attacks

    microsoft edge

    A recently disclosed Internet Explorer vulnerability is waiting for a fix from Microsoft. Though the company has released a micro-patch to restrict hackers from stealing files or running any surveillance on the victim’s computer, the risk is still there.

    Read: Microsoft Releases First Test Build of Chromium-based Edge Browser

    A security researcher John Page has discovered an XML External Entity (XXE) security flaw in the browser. He reported the issue to Microsoft on March 27 and also published all the details including the proof-of-concept code on April 10.

    Modern web browsers are no longer supporting .MHT files (IE’s web archives format) and so whenever a user tries to open such files, the request got automatically handled by Internet Explorer.

    Mitja Kolsek, a security analyst at ACROS, also examined the issue and learned that it’s an “undocumented security feature” in Edge that clashes with IE’s capability to correctly read the mark of the web (MOTW) flag applied to files downloaded from the Internet.

    Though Microsoft hasn’t released a fix yet, a micro-patch is available through the 0Patch platform. It’s equipped with error-checking routines that allow Internet Explorer to understand the mark of the web flag Edge sets correctly.

    Conflict Between Security Features

    Microsoft Edge File Permissions Conflicts with IE
    Source: Bleeping Computer

    MOTW is a security feature that makes sure that Internet Explorer will ask for permission before running active content and local scripts with elevated privileges.

    As per the explanation by Microsoft, “In short the MOTW in a page allows the content to run as if from the Internet zone. So the script and active content will have the same privileges as if you were viewing it from a website and not be able to run with elevated access to machine resources.

    Mitja also found that the permissions for MHT files downloaded with Internet Explorer are different from those downloaded by Edge. It also appears that MOTW information is stored in the data stream but Internet Explorer faces an error while reading it. The consequences are browser ignores the error and the file gets the same treatment as regular local files, as it doesn’t have the MOTW flag.

    It’s also important to note that XXE vulnerability only puts Microsoft Edge users at risk. Page didn’t find any undocumented feature that makes other browsers and email clients vulnerable to exploitation.

    Share. Facebook Twitter LinkedIn Tumblr Reddit Telegram WhatsApp
    Subham Kapiswe
    • LinkedIn

    A computer science engineer by education and blogger by profession who loves to write about Programming, Cybersecurity, Blockchain, Artificial Intelligence, Open Source and other latest technologies.

    Related Posts

    NVIDIA GeForce NOW is Finally Coming to India

    January 8, 2025

    India’s JioGamesCloud Added 100+ New Games

    October 15, 2023

    Apple’s latest iOS 16.6 Patch Boosts iPhone Privacy & Security

    July 31, 2023

    Multiview Feature Now Available on YouTube Tv

    July 31, 2023

    Threads’ to Recieve DM Support Soon, Confirms Meta Spokesperson

    July 30, 2023

    Capgemini to Sink 2 billion Euros in AI Following Half-Year Sales

    July 29, 2023
    Lists You May Like

    10 Best RARBG Alternative Sites in April 2025 [Working Links]

    April 1, 2025

    The Pirate Bay Proxy List in 2025 [Updated List]

    January 2, 2025

    10 Sites to Watch Free Korean Drama [2025 Edition]

    January 2, 2025

    10 Best Torrent Search Engine Sites (2025 Edition)

    February 12, 2025

    10 Best GTA V Roleplay Servers in 2025 (Updated List)

    January 6, 2025

    5 Best Torrent Sites for Software in 2025

    January 2, 2025

    1337x Alternatives, Proxies, and Mirror Sites in 2025

    January 2, 2025

    10 Best Torrent Sites for eBooks in 2025 [Working]

    January 2, 2025

    10 Best Anime Torrent Sites in 2025 [Working Sites]

    January 6, 2025

    Top Free Photo Editing Software For PC in 2025

    January 2, 2025
    Pages
    • About
    • Contact
    • Privacy
    • Careers
    Privacy

    Information such as the type of browser being used, its operating system, and your IP address is gathered in order to enhance your online experience.

    © 2013 - 2025 Technotification | All rights reserved.

    Type above and press Enter to search. Press Esc to cancel.