Proxy Execution with Microsoft Edge WebView2 w/ Matthew Eidelberg

Proxy Execution with Microsoft Edge WebView2 w/ Matthew Eidelberg

Source: YouTube · Black Hills Information Security · published Apr 17, 2026 · 1:09:03

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

[BLUF] Matthew Igelburg demonstrates how Microsoft Edge WebView2, a core component of modern "Windows Apps," reintroduces DLL side-loading vulnerabilities by relying on user-writable appdata paths for critical DLLs, effectively bypassing sandbox security controls.

Key Takeaways:
• WebView2 enables modern Windows Apps but loads critical DLLs like domain_actions.dll from user-writable appdata folders, reintroducing DLL hijacking risks 10:15
• The speaker details weaponizing this via the "Facedancer" tool to generate proxy-based DLLs that redirect execution to malicious code while maintaining stability 20:30
• Microsoft declined to fix the issue, reclassifying it as a "forever day" vulnerability due to the widespread dependency of core OS functions on WebView2 35:45

[Closing statement] This session highlights a critical architectural flaw in Microsoft's security strategy, where legacy attack vectors persist within modern sandboxed applications due to unresolved vendor dependencies.

Sources:

  • 0:00 Introduction to proxy execution with MS Edge WebView2
  • 10:15 Analysis of WebView2 DLL loading from appdata
  • 20:30 Demonstration of Facedancer tool functionality
  • 35:45 Disclosure process and "forever day" classification

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

All right, hello everybody. Welcome to the BHIS webcast for today. We've got Matthew Igelburg here. He's going to talk to us about Microsoft stuff cuz I keep forgetting exactly what the title is, but he's going to tell us anyway in just a moment. I'm going to go backstage and at the end of the webcast we're going to come back. We're going to talk about questions that may have come up and uh maybe more food stuff or not, but anyway, it's all yours Matthew. Take it away. Thank you. Let's get started. So, the title is proxy execution using or with MS Edge Web View 2. So, we're going to kind of talk about a lot of concepts today, some old, some new, and the kind of bridge between them. So, of course, as I mentioned, some old, we're going to kind of recap DLL attacks just to level set the knowl…