Researchers reported an unpatched NTLM credential coercion flaw in the Windows Explorer search: URI handler that can force a victim system to authenticate to an attacker-controlled SMB server and expose a Net-NTLMv2 hash after a single click on a crafted link. Testing showed the behavior worked on Windows 11 25H2 Pro with default Microsoft Defender settings, required no malware or elevated privileges, and could be triggered from both a command line and an Edge hyperlink that invoked the handler.
The issue was described as materially equivalent to Microsoft-patched CVE-2026-33829 in the Windows Snipping Tool because both involve unsafe URI parameter handling that leads to outbound UNC access and NTLM authentication. Huntress said Microsoft rated the search: issue as Moderate and declined to issue a fix, while analysis indicated search: and search-ms: share the same DelegateExecute CLSID and COM activation path in ExplorerFrame.dll, suggesting any durable remediation would need to occur in SearchExecute or related Explorer code rather than only at the URI-scheme layer. Recommended mitigations include blocking outbound SMB, enforcing SMB signing, restricting or disabling NTLM, and monitoring for search: and search-ms: URIs in email and proxy logs.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Huntress reported notifying Microsoft about the Windows search: URI NTLM hash leakage issue on 2026-04-15. Microsoft declined to service the vulnerability because it did not meet the threshold for Important or Critical severity.
Huntress published details of an NTLM credential coercion issue in Windows Explorer's search: URI handler that can leak a victim's Net-NTLMv2 hash to an attacker-controlled SMB server after a single click on a crafted link. The post says Microsoft Security Response Center rated the issue Moderate and declined to service it, while Huntress recommended mitigations such as blocking outbound SMB and restricting NTLM.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourcehuntress.com
Open sourcehuntress.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.