logo

Windows Search URI Handler Vulnerability Exposes NTLMv2 Hashes to Remote Attackers

ID: e29f5a41-eb58-5385-9216-4ad14a4ee547

STIX ID: report--e29f5a41-eb58-5385-9216-4ad14a4ee547

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-06-03

Date Updated: 2026-06-03

Author: Divya

...
...

Security researchers observed that Windows' search: and search-ms: URI handlers improperly validate user-supplied parameters, enabling an attacker to embed a UNC path in a crafted URI that forces the system to perform NTLM authentication to an attacker-controlled SMB server, leaking Net-NTLMv2 hashes. The issue requires only a single click (no malware), is unpatched and triaged below servicing threshold by Microsoft, and carries practical enterprise risk via NTLM relay, offline cracking, and lateral movement; recommended mitigations include blocking outbound SMB, enforcing SMB signing, restricting NTLM, and monitoring for suspicious URI and SMB activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.