>_
The Fuzz.

The archive

1 post · filtered by Threat Intel

>
$ open --post cve-2026-3
Threat Intel

CVE-2026-33829: NTLM leak via the Snipping Tool deep link

A one-click NTLM coercion in the Windows Snipping Tool. The ms-screensketch URI handler accepts an unvalidated UNC path in filePath and opens it directly, leaking the user's Net-NTLMv2 response to any reachable SMB server. Walkthrough, working PoC, and detection.

Apr 17, 20269 min