
Proxy Execution with Microsoft Edge WebView2 w/ Matthew Eidelberg
Source: YouTube · Black Hills Information Security · published Apr 17, 2026 · 1:09:03
[BLUF] Matthew Igelburg demonstrates how Microsoft Edge WebView2, a core component of modern "Windows Apps," reintroduces DLL side-loading vulnerabilities by relying on user-writable appdata paths for critical DLLs, effectively bypassing sandbox security controls.
Key Takeaways:
• WebView2 enables modern Windows Apps but loads critical DLLs like domain_actions.dll from user-writable appdata folders, reintroducing DLL hijacking risks 10:15
• The speaker details weaponizing this via the "Facedancer" tool to generate proxy-based DLLs that redirect execution to malicious code while maintaining stability 20:30
• Microsoft declined to fix the issue, reclassifying it as a "forever day" vulnerability due to the widespread dependency of core OS functions on WebView2 35:45
[Closing statement] This session highlights a critical architectural flaw in Microsoft's security strategy, where legacy attack vectors persist within modern sandboxed applications due to unresolved vendor dependencies.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
All right, hello everybody. Welcome to the BHIS webcast for today. We've got Matthew Igelburg here. He's going to talk to us about Microsoft stuff cuz I keep forgetting exactly what the title is, but he's going to tell us anyway in just a moment. I'm going to go backstage and at the end of the webcast we're going to come back. We're going to talk about questions that may have come up and uh maybe more food stuff or not, but anyway, it's all yours Matthew. Take it away. Thank you. Let's get started. So, the title is proxy execution using or with MS Edge Web View 2. So, we're going to kind of talk about a lot of concepts today, some old, some new, and the kind of bridge between them. So, of course, as I mentioned, some old, we're going to kind of recap DLL attacks just to level set the knowl…