Unpatched Windows Search URI Vulnerability Lets Attackers Steal NTLMv2 Hashes
News Source : Internet
News Summary
- Researchers have disclosed details of an unpatched issue that could be exploited to disclose a user's NTLMv2 hash to the attacker.
- CVE-2026-33829 refers to a spoofing vulnerability that could expose sensitive information to an unauthorized actor.
- The newly discovered shortcoming achieves the same end goal using "search:" and "crumb=location:" instead of "filePath" using a command like below.
- In the absence of a fix, it's advised to block outbound SMB (TCP/445 and TCP/139) on hosts that don't need it.
Cybersecurity researchers have disclosed details of an unpatched issue that could be exploited to disclose a users NTLMv2 hash to the attacker.
Never miss a story from us, subscribe to our newsletter