Windows Search URI Handler Vulnerability Exposes NTLMv2 Hashes to Remote Attackers
ID: e29f5a41-eb58-5385-9216-4ad14a4ee547
STIX ID: report--e29f5a41-eb58-5385-9216-4ad14a4ee547
Feed Name: GBHackers
Security researchers observed that Windows' search: and search-ms: URI handlers improperly validate user-supplied parameters, enabling an attacker to embed a UNC path in a crafted URI that forces the system to perform NTLM authentication to an attacker-controlled SMB server, leaking Net-NTLMv2 hashes. The issue requires only a single click (no malware), is unpatched and triaged below servicing threshold by Microsoft, and carries practical enterprise risk via NTLM relay, offline cracking, and lateral movement; recommended mitigations include blocking outbound SMB, enforcing SMB signing, restricting NTLM, and monitoring for suspicious URI and SMB activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
