Windows Snipping Tool Vulnerability Allows Attackers to Perform Network Spoofing
ID: b53441b1-cc4c-5653-9bfc-a074ce9d98ae
STIX ID: report--b53441b1-cc4c-5653-9bfc-a074ce9d98ae
Feed Name: Cyber Press
Threat Score
A newly disclosed vulnerability (CVE-2026-33829) in Microsoft Snipping Tool's ms-screensketch deep link handling can be abused to force the app to connect to attacker-controlled SMB shares, leaking Net-NTLM hashes. Exploitation requires minimal user interaction (e.g., opening a crafted URI or visiting a malicious page); proof-of-concept details were published and Microsoft released a patch on April 14, 2026—administrators are urged to apply the April 2026 Windows Security Update.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
