CVE-2026-33829 is a spoofing and information disclosure vulnerability in Microsoft Windows Snipping Tool caused by improper validation of input supplied through the application's registered ms-screensketch URI handler. The vulnerable deep-link handling logic accepts a filePath parameter and can be induced to access an attacker-controlled UNC path over SMB. When the target system attempts that remote access, Windows automatically performs NTLM authentication in the security context of the current user, exposing the user's Net-NTLMv2 authentication material to the remote server. Exploitation is typically achieved by convincing a user to open a crafted link from a web page, email, or other URL source that launches Snipping Tool with attacker-controlled parameters. The application may appear to open normally while the credential leakage occurs in the background.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 5 candidates as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
31 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously patched vulnerability in the Windows Snipping Tool referenced as similar to the newly disclosed Windows search URI handler NTLMv2 hash leakage issue.
A spoofing vulnerability in the Windows Snipping Tool ms-screensketch: URI handler that can disclose a user's NTLMv2/Net-NTLMv2 hash by causing the system to connect to an attacker-controlled SMB/UNC path.
An NTLM credential leakage vulnerability in Microsoft Snipping Tool's ms-screensketch URI handler that can trigger outbound SMB authentication and expose Net-NTLMv2 hashes via a remote UNC path.
A vulnerability in Microsoft Windows Snipping Tool’s handling of the ms-screensketch deep link URI allows an attacker to supply a UNC path via the filePath parameter, coercing an authenticated SMB connection and exposing the victim’s Net-NTLM hash.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.