vendor:
Windows MSHTA.EXE .HTA File
by:
hyp3rlinx
N/A
CVSS
N/A
XML External Entity Injection
CWE
Product Name: Windows MSHTA.EXE .HTA File
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows
2020
Microsoft Windows mshta.exe 2019 – XML External Entity Injection
Windows mshta.exe allows processing of XML External Entities, resulting in local data theft and program reconnaissance upon opening specially crafted HTA files. The exploit leverages XML injection targeting the mshta.exe HTA file type, providing stealthy data theft with recon capabilities.