Unpatched Windows Search URI Vulnerability Lets Attackers Steal NTLMv2 Hashes
A newly disclosed, unpatched vulnerability in the Windows Search URI handler allows attackers to steal users' NTLMv2 hashes by inducing them to click specially crafted links that connect to malicious SMB servers. This issue, similar to a previously patched flaw in the Windows Snipping Tool, poses risks of relay attacks and deeper network access, but Microsoft has declined to issue a fix, recommending mitigations like blocking outbound SMB traffic and disabling NTLM where possible.
https://thehackernews.com/2026/06/unpatched-windows-search-uri.html













