Hackers have discovered a vulnerability in Windows to attack through the outdated and disabled Internet Explorer browser, despite Microsoft's security measures. They use files with the .url and .hta shortcuts. If the user confirms their opening, malware is immediately downloaded onto their computer.

Cybersecurity experts from Check Point have discovered a new scheme for attacking computers running Windows 10 and Windows 11, exploiting a vulnerability in the outdated Internet Explorer browser. PCMag. Although Microsoft officially ended support for Internet Explorer and permanently disabled it in its operating system last year, hackers have found a way to install malware through it.

Check Point researcher Haifei Li , that attackers use Windows shortcut files with the .url extension, which can be configured to launch Internet Explorer. This method does not circumvent the modern security systems present in newer browsers like Chrome or Edge.
The attack is particularly effective when using phishing emails or malicious attachments. Li found that hackers disguise shortcuts as PDF files. When such a shortcut is opened, Internet Explorer downloads the malware as an .hta file if the user confirms all prompts.

Will Dorman, a security expert, noted that modern browsers block the download of .hta files, while Internet Explorer only displays a text warning, which users may easily overlook due to ignorance. The especially dangerous aspect is that Microsoft has stopped releasing security updates for Internet Explorer, which allows hackers to exploit unpatched vulnerabilities through this browser.
Check Point's research has shown that these attacks have been carried out since at least January 2023. The good news is that in response to the discovered vulnerability, Microsoft released a patch that prevents Internet Explorer from launching via shortcut files. Experts also recommend that Windows users be particularly cautious when handling files with .url extensions received from unreliable sources.
Source:
Source: 3dnews.ru
