$ open --post cve-2026-3…
Threat Intel
CVE-2026-33829: NTLM leak via the Snipping Tool deep link
A one-click NTLM coercion in the Windows Snipping Tool. The ms-screensketch URI handler accepts an unvalidated UNC path in filePath and opens it directly, leaking the user's Net-NTLMv2 response to any reachable SMB server. Walkthrough, working PoC, and detection.
Apr 17, 20269 min