BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

New Windows Search Flaw Leaks NTLM Passwords

Unpatched Windows search flaw leaks NTLMv2 hashes via malicious links; Microsoft declines fix.

  • An unpatched vulnerability in the Windows search URI handler can leak a user’s sensitive NTLMv2 authentication hash.
  • The flaw allows attackers to capture hashes via specially crafted links, similar to a patched issue, CVE-2026-33829, in the Snipping Tool.
  • Microsoft declined to fix the issue, rating it below their servicing bar for security updates.
  • Experts recommend blocking outbound SMB traffic and enforcing SMB signing to mitigate the risk.

Cybersecurity researchers disclosed an unpatched vulnerability in June 2026 that exposes users’ NTLMv2 hashes. This flaw, found in the Windows search: URI handler, was documented by Huntress.

- Advertisement -

Like a previous spoofing vulnerability, CVE-2026-33829, this issue can be triggered by a malicious link. Consequently, clicking such a link forces the system to connect to an attacker-controlled server.

Specifically, the attack uses a “crumb=location:” parameter to initiate the connection. This mechanism, CVE-2023-35636, was previously documented by Varonis for stealing hashes.

The captured NTLMv2 hash can then be used in relay attacks. Attackers leverage these to gain deeper network access.

Following responsible disclosure on April 15, 2026, Microsoft declined to release a patch. The company stated “only Important and Critical severity cases meet our bar for servicing.”

- Advertisement -

Security professionals now advise blocking outbound SMB ports on non-essential hosts. Meanwhile, enforcing SMB signing and disabling NTLM where possible are also recommended defenses.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Sonic Labs Keeps Fantom Opera Open

Fantom Opera will remain live with a funded bridge until at least year-end, reversing...

Massive FortiBleed Attack Hits Over 430,000 Firewalls

A financially-motivated initial access broker has targeted over 430,000 FortiGate firewalls globally since February...

Catholic Leaders Oppose Crypto Clarity Act Over Trafficking

A coalition of Catholic leaders urged U.S. Senate leaders to oppose a key section...

Cardano wallets drained, $2.4M lost in SecondFi exploit

SecondFi's wallet generation software was exploited, draining roughly 16 million ADA (~$2.4 million).The company...

Bitcoin OGs Cut Spending to Lowest Level in 19 Months

Bitcoin holders who acquired their coins over five years ago have reduced their spending...

Must Read

26 Best Investment Audiobooks on Audible

Looking to expand your financial knowledge? Me too..When I first started investing, I was completely lost. There were so many terms, strategies, and theories...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading