logo

Unpatched Windows Search URI Vulnerability Lets Attackers Steal NTLMv2 Hashes

ID: f42d1a2f-3fdc-5883-9014-4881a43b0f82

STIX ID: report--f42d1a2f-3fdc-5883-9014-4881a43b0f82

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-06-03

Date Updated: 2026-06-03

Author: [email protected] (The Hacker News)

...
...

Researchers disclosed an unpatched Windows search: URI handler flaw where a crafted URL using a "crumb=location:" UNC path can trigger SMB authentication to an attacker-controlled server and leak the user's Net-NTLMv2 hash. The behavior mirrors a previously patched Snipping Tool URI vulnerability (CVE-2026-33829); Microsoft declined to patch this issue after responsible disclosure. Captured hashes can be used for relay attacks and lateral movement. Short-term mitigations include blocking outbound SMB (TCP/445 and TCP/139), enforcing SMB signing, and disabling NTLM where feasible.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.