{"id":12190,"date":"2026-04-17T10:03:45","date_gmt":"2026-04-17T10:03:45","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/04\/17\/windows-snipping-tool-vulnerability-allows-attacker-to-perform-spoofing-over-a-network\/"},"modified":"2026-04-17T10:03:45","modified_gmt":"2026-04-17T10:03:45","slug":"windows-snipping-tool-vulnerability-allows-attacker-to-perform-spoofing-over-a-network","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/04\/17\/windows-snipping-tool-vulnerability-allows-attacker-to-perform-spoofing-over-a-network\/","title":{"rendered":"Windows Snipping Tool Vulnerability Allows Attacker to Perform Spoofing Over a Network"},"content":{"rendered":"<p>    Windows Snipping Tool Vulnerability Allows Attacker to Perform Spoofing Over a Network<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Microsoft has addressed a moderate-severity security flaw in the Windows Snipping Tool that could allow malicious actors to steal user credentials.<\/p>\n<p>Tracked as CVE-2026-33829, this <a href=\"https:\/\/cybersecuritynews.com\/microsoft-office-spoofing-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">spoofing vulnerability <\/a>was officially patched during the April 14, 2026, security updates.<\/p>\n<p>Discovered and reported by security researchers at Blackarrow (Tarlogic), the flaw highlights the ongoing risks associated with application <a href=\"https:\/\/cybersecuritynews.com\/pdf-zero-day-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">URL handlers in Windows environments.<\/a><\/p>\n<p>CVE-2026-33829 holds a CVSS 3.1 score of 4.3 and is classified as an exposure of <a href=\"https:\/\/cybersecuritynews.com\/oppo-clone-phone-weak-wifi-hotspot\/\" target=\"_blank\" rel=\"noreferrer noopener\">sensitive information to unauthorized actors (CWE-200)<\/a>.<\/p>\n<p>The vulnerability resides in how the Windows Snipping Tool processes deep links. Specifically, the application fails to validate input when handling the\u00a0<code>ms-screensketch<\/code>\u00a0URI schema properly.<\/p>\n<p>According to the vulnerability disclosure provided by Microsoft and Blackarrow, an attacker can exploit this <a href=\"https:\/\/cybersecuritynews.com\/smbleed-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">weakness to force an authenticated Server Message Block (SMB) connection<\/a> to a remote, attacker-controlled server.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-spoofing-flaw-exposes-snipping-tool\"><strong>Spoofing Flaw Exposes Snipping Tool<\/strong><\/h2>\n<p>While the exploit requires user interaction, the attack complexity is considered low. Here is how the attack chain operates based on the released proof-of-concept:<\/p>\n<ul class=\"wp-block-list\">\n<li>\n<strong>Malicious Link Creation:<\/strong> Attackers craft a specific web link using the\u00a0<code>ms-screensketch: edit<\/code>\u00a0parameter.<\/li>\n<li>\n<strong>Deceptive Routing:<\/strong> The link points the\u00a0filePath\u00a0parameter to a malicious external SMB server.<\/li>\n<li>\n<strong>User Interaction:<\/strong> The attacker tricks the victim into <a href=\"https:\/\/cybersecuritynews.com\/metamask-users-targeted-with-phishing-emails\/\" target=\"_blank\" rel=\"noreferrer noopener\">clicking a link in a phishing email<\/a> or on a compromised website, prompting the user to confirm launching the Snipping Tool program.<\/li>\n<li>\n<strong>Hash Theft:<\/strong> Once approved, Snipping Tool connects to the remote server to fetch the fake file, silently leaking the user\u2019s NTLMv2 password hash in the background.<\/li>\n<li>\n<strong>Unauthorized Access:<\/strong> The attacker captures this hash and can use it to authenticate as the compromised user on the network.<\/li>\n<\/ul>\n<p>Security experts warn that this vulnerability is highly adaptable for social engineering campaigns. An attacker could send a legitimate-looking webpage asking a user to crop a corporate wallpaper or edit a badge photo.<\/p>\n<p>While the Snipping Tool opens normally on the user\u2019s screen, making the request appear harmless, <a href=\"https:\/\/cybersecuritynews.com\/new-red-team-technique-remotemonologue\/\" target=\"_blank\" rel=\"noreferrer noopener\">NTLM authentication occurs invisibly<\/a>.<\/p>\n<p>Although successful exploitation results in a loss of confidentiality, it does not allow the attacker to alter data (Integrity) or crash the system (Availability).<\/p>\n<p><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-33829\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Microsoft notes that the exploit code maturity is currently unproven<\/a>, and actual exploitation remains \u201cUnlikely.\u201d There are no reports of it being exploited in the wild.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-affected-systems\"><strong>Affected Systems<\/strong><\/h2>\n<p><a href=\"https:\/\/github.com\/blackarrowsec\/redteam-research\/tree\/master\/CVE-2026-33829\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">The vulnerability, detailed on GitHub, impacts a wide range of Microsoft operating systems<\/a>, including multiple versions of Windows 10, Windows 11, and Windows Server from 2012 through 2025.<\/p>\n<p>To secure networks against CVE-2026-33829, organizations should implement the following mitigation strategies:<\/p>\n<ul class=\"wp-block-list\">\n<li>Immediately apply the official <a href=\"https:\/\/cybersecuritynews.com\/microsoft-cumulative-update-windows-11\/\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft security patches<\/a> released on April 14, 2026.<\/li>\n<li>Block outbound SMB traffic (Port 445) at the network perimeter to prevent NTLM hashes from communicating with external servers.<\/li>\n<li>Educate employees about the dangers of clicking unknown links and unquestioningly approving application launch prompts from web browsers.<\/li>\n<\/ul>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/windows-snipping-tool-vulnerability\/\">Windows Snipping Tool Vulnerability Allows Attacker to Perform Spoofing Over a Network<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/windows-snipping-tool-vulnerability\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Windows Snipping Tool Vulnerability Allows Attacker to Perform Spoofing Over a Network Microsoft has addressed a moderate-severity security flaw in the Windows Snipping Tool that could allow malicious actors to steal user credentials. Tracked as CVE-2026-33829, this spoofing vulnerability was officially patched during the April 14, 2026, security updates. Discovered and reported by security researchers [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,158,648],"tags":[130],"class_list":["post-12190","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-microsoft","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12190"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=12190"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12190\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=12190"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=12190"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=12190"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}