Microsoft has patched CVE-2026-33829, a spoofing vulnerability in the Windows Snipping Tool that can trigger an authenticated SMB connection to an attacker-controlled server and expose a victim’s NTLMv2 password hash. The flaw stems from improper validation of deep links using the ms-screensketch URI scheme, allowing attackers to coerce the application into initiating network authentication and leaking credentials over the network.
Researchers at Blackarrow (Tarlogic) reported the issue, which Microsoft rated moderate severity with a CVSS 3.1 score of 4.3 and said was not known to be exploited in the wild. Exploitation requires user interaction, such as clicking a malicious link in a phishing email or on a compromised website, but the attack complexity is considered low. Affected systems include multiple Windows 10, Windows 11, and Windows Server releases, and recommended defenses include applying Microsoft’s update, blocking outbound SMB traffic on port 445, and warning users against suspicious links and application launch prompts.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
After Microsoft issued its April 14, 2026 patch, Black Arrow researchers published a coordinated advisory and proof-of-concept exploit for the Snipping Tool NTLM hash leak vulnerability. The PoC demonstrated abuse of the ms-screensketch deep link with a UNC path to trigger outbound SMB authentication and expose a victim's Net-NTLM hash.
Public coverage described how the flaw abuses the ms-screensketch deep-link handler to coerce outbound SMB authentication and leak NTLMv2 hashes. Reports also identified affected Windows 10, Windows 11, and Windows Server versions and highlighted mitigations such as patching and blocking outbound SMB on port 445.
Microsoft published CVE-2026-33829 in its Security Update Guide as part of the April 14, 2026 security updates. The company rated the Windows Snipping Tool spoofing flaw as moderate severity, said exploitation was less likely, and noted no known in-the-wild exploitation.
Blackarrow researchers at Tarlogic discovered a spoofing vulnerability in the Windows Snipping Tool involving improper validation of the ms-screensketch URI scheme and reported it to Microsoft. The issue could trigger an authenticated SMB connection to an attacker-controlled server and expose the victim's NTLMv2 hash.
BlackarrowSec researchers reported the Snipping Tool NTLM hash disclosure vulnerability to Microsoft through responsible disclosure. The disclosure occurred ahead of Microsoft's April 2026 security updates.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourcegithub.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.