Unpatched NTLM Vulnerability in Windows URI Handlers Exposes Credentials

Unpatched NTLM Vulnerability in Windows URI Handlers Exposes Credentials

3 Jun 2026 HuntressCybersecuritynewsGbhackersgithub.comwww.varonis.com 92% similarity 48.9
Share:

Article Content

Browse articles
ThreatCluster

A newly identified flaw in Windows URI handlers can leak NTLMv2 hashes to attacker-controlled servers with a single link click. This vulnerability is related to CVE-2026-33829, which was patched in the Windows Snipping Tool on April 14, 2026, but no CVE has been assigned for this variant. The issue arises from the ms-screensketch: URI handler, which does not validate the filePath parameter, allowing NTLM authentication to be triggered and exposing sensitive credentials. Attackers can exploit this flaw without requiring malware, merely by tricking users into clicking a link. The vulnerability affects Windows systems running the Snipping Tool and similar URI handlers. As of now, Microsoft has not provided a fix or acknowledged the new variant. Security professionals are urged to remain vigilant as this could facilitate unauthorized access to networks.

Key Points: • A new NTLM vulnerability allows credential leakage via Windows URI handlers. • The flaw is similar to CVE-2026-33829 but lacks a CVE and fix. • Exploitation requires only a user to click a specially crafted link.

ThreatCluster AI

Timeline

2026-04-14
CVE-2026-33829 published
Microsoft patched an NTLM credential coercion bug in the Windows Snipping Tool with a CVSS score of 4.3.
Huntress
2026-05-21
First public PoC for CVE-2026-33829
A proof of concept was publicly shared demonstrating the vulnerability in the Snipping Tool.
Huntress
2026-06-02
New NTLM vulnerability reported
A similar NTLM leakage issue in another Windows URI handler was reported, with no CVE assigned.
Huntress
2026-06-03
Cybersecurity news coverage
Cybersecurity news outlets reported on the new NTLM vulnerability and its implications for Windows users.
Cybersecuritynews

Community

Browse all →