Windows Search URI Handler Flaw Leaks NTLMv2 Hashes to Attacker-Controlled Servers

A newly disclosed flaw in the Windows search URI handler can silently leak NTLMv2 hashes to attacker-controlled servers with nothing more than a single link click. This behavior is the same bug class as CVE-2026-33829 in the Snipping Tool, but Microsoft has assigned no CVE and shipped no fix for this variant. On April 14, 2026, Microsoft […]

The post Windows Search URI Handler Flaw Leaks NTLMv2 Hashes to Attacker-Controlled Servers appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: