BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

New Windows Search Flaw Leaks NTLM Passwords

Unpatched Windows search flaw leaks NTLMv2 hashes via malicious links; Microsoft declines fix.

  • An unpatched vulnerability in the Windows search URI handler can leak a user’s sensitive NTLMv2 authentication hash.
  • The flaw allows attackers to capture hashes via specially crafted links, similar to a patched issue, CVE-2026-33829, in the Snipping Tool.
  • Microsoft declined to fix the issue, rating it below their servicing bar for security updates.
  • Experts recommend blocking outbound SMB traffic and enforcing SMB signing to mitigate the risk.

Cybersecurity researchers disclosed an unpatched vulnerability in June 2026 that exposes users’ NTLMv2 hashes. This flaw, found in the Windows search: URI handler, was documented by Huntress.

- Advertisement -

Like a previous spoofing vulnerability, CVE-2026-33829, this issue can be triggered by a malicious link. Consequently, clicking such a link forces the system to connect to an attacker-controlled server.

Specifically, the attack uses a “crumb=location:” parameter to initiate the connection. This mechanism, CVE-2023-35636, was previously documented by Varonis for stealing hashes.

The captured NTLMv2 hash can then be used in relay attacks. Attackers leverage these to gain deeper network access.

Following responsible disclosure on April 15, 2026, Microsoft declined to release a patch. The company stated “only Important and Critical severity cases meet our bar for servicing.”

- Advertisement -

Security professionals now advise blocking outbound SMB ports on non-essential hosts. Meanwhile, enforcing SMB signing and disabling NTLM where possible are also recommended defenses.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

“Bitcoin Rodney” Pleads Guilty in $1.8 Billion Crypto Fraud

A Florida man, Rodney "Bitcoin Rodney" Burton, pleaded guilty to conspiracy tied to an...

Coinbase bets on AI, expands beyond crypto trading

Coinbase launched three major AI products and broader financial tools, positioning itself as "the...

Malware-Laced Steam Wallpapers Steal Crypto Wallets

Malware hidden in Steam Workshop wallpaper downloads is stealing crypto wallet data and installing...

EU MiCA Deadline Looms as US CBDC Ban Advances

The EU's MiCA licensing deadline on July 1 is pressuring exchanges, with BitGo launching...

Malicious JetBrains Plugins Steal AI Keys

Fifteen malicious plugins on the JetBrains Marketplace have been stealing AI provider API keys...

Must Read

Top 10 Best Blockchain Games

If you want to know about the best blockchain games then read this article carefully. We listed the best games you can play and...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading