CVE-2026-33829Disclosure(microsoft / windows_10_1607)

CRITICALCVSS 4.3 · MEDIUM

Exploitation observed; activity peaked at 6 mentions and remains active

Immediate actions

  • Patch microsoft windows_10_1607 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform spoofing over a network.

8.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2
  • windows_10_22h2

Threat summary

  • Active exploitation appears in 3 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 37 mentions across 15 observed days

What's happening

  • Active exploitation reported across 3 signals
  • Exploit tool or code specified in 6 signals
  • PoC mentioned or linked in 9 signals
  • Patch or workaround mentioned in 9 signals
  • Technical details provided in 30 signals
  • Disclosure: 12 classified signals
  • General: 9 classified signals
  • Peaked 10d ago at 6 mentions (2026-04-19); latest day: 1
  • 37 total mentions across 15 days

Affected systems

Vendors
Products
windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_23h2windows_11_24h2windows_11_25h2windows_11_26h1windows_server_2012windows_server_2016

2 versions affected across 14 products

Deep dive

Activity timeline37 mentions / 15d
02356Mentions · 2026-04-15: 4Mentions · 2026-04-16: 3Mentions · 2026-04-17: 3Mentions · 2026-04-18: 2Mentions · 2026-04-19: 6Mentions · 2026-04-20: 3Mentions · 2026-04-21: 6Mentions · 2026-04-24: 2Mentions · 2026-04-28: 1Mentions · 2026-05-17: 1Mentions · 2026-05-22: 1Mentions · 2026-06-10: 1Mentions · 2026-06-18: 1Mentions · 2026-06-19: 2Mentions · 2026-06-20: 1PoC Mentioned / Linked · 2026-04-15: 1PoC Mentioned / Linked · 2026-04-16: 1PoC Mentioned / Linked · 2026-04-17: 1PoC Mentioned / Linked · 2026-04-19: 1PoC Mentioned / Linked · 2026-04-21: 3PoC Mentioned / Linked · 2026-04-24: 1PoC Mentioned / Linked · 2026-06-19: 1Exploit Tool / Code · 2026-04-16: 1Exploit Tool / Code · 2026-04-17: 1Exploit Tool / Code · 2026-04-19: 1Exploit Tool / Code · 2026-04-21: 2Exploit Tool / Code · 2026-04-24: 1Active Exploitation · 2026-04-18: 1Active Exploitation · 2026-04-19: 1Active Exploitation · 2026-06-10: 1Patch / Workaround · 2026-04-15: 1Patch / Workaround · 2026-04-16: 1Patch / Workaround · 2026-04-18: 2Patch / Workaround · 2026-04-19: 1Patch / Workaround · 2026-04-20: 1Patch / Workaround · 2026-04-21: 1Patch / Workaround · 2026-04-24: 1Patch / Workaround · 2026-06-20: 1Technical Details · 2026-04-15: 4Technical Details · 2026-04-16: 3Technical Details · 2026-04-17: 3Technical Details · 2026-04-18: 2Technical Details · 2026-04-19: 2Technical Details · 2026-04-20: 2Technical Details · 2026-04-21: 5Technical Details · 2026-04-24: 2Technical Details · 2026-04-28: 1Technical Details · 2026-05-22: 1Technical Details · 2026-06-10: 1Technical Details · 2026-06-18: 1Technical Details · 2026-06-19: 2Technical Details · 2026-06-20: 104-1504-1604-1704-1804-1904-2004-2104-2404-2805-1705-2206-1006-1806-1906-20
Signal classification6 categories
Disclosure
1232.4%
General
924.3%
PoC
821.6%
Patch
513.5%
Exploit
25.4%
Active Exploitation
12.7%
Referenced assets19 URLs
Classification over time
DateTotalLabels
2026-04-154
Disclosure1General2Patch1
2026-04-163
Disclosure1Patch1PoC1
2026-04-173
Disclosure2PoC1
2026-04-182
Patch2
2026-04-196
Active Exploitation1Disclosure1Exploit1General2PoC1
2026-04-203
Disclosure1General1Patch1
2026-04-216
Disclosure3PoC3
2026-04-242
General1PoC1
2026-04-281
Disclosure1
2026-05-171
General1
2026-05-221
Disclosure1
2026-06-101
Exploit1
2026-06-181
General1
2026-06-192
Disclosure1PoC1
2026-06-201
General1
Full discourse20 posts
  • BlackArrow@BlackArrowSec
    Patch

    Microsoft has addressed a one-click NTLM leak vulnerability affecting Windows Snipping Tool (CVE-2026-33829), discovered by our researcher Marcos Díaz (@Calvaruga). ➡️ Read the write-up: https://github.com/blackarrowsec/redteam-research/tree/master/CVE-2026-33829 ➡️ Microsoft bulletin: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33829 https://t.co/YqxbwlqfRP

    Post summary

    Microsoft released a patch for the NY 2026-33829 NTLM leak in Snipping Tool; the post confirms remediation but not active exploitation or PoC details.

    61437565348113.3K
    1.8K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    شباب اداة تصوير الشاشة في ويندوز فيها ثغره اتكلم جد ما امزح😅😅 والله مايكروسوفت هالشهر مبدعين باقي ثغرة في زر Start CVE-2026-33829 https://t.co/Hi0vkgNWR8

    Post summary

    The post reports a Windows screenshot tool vulnerability (CVE‑2026‑33829) with a link to more information, but offers no technical details, PoC, or evidence of exploitation.

    2311120819690.5K
    49.3K followersView on X
  • 7h3h4ckv157@7h3h4ckv157
    General

    The NTLM leakage primitive in the Windows search: URI handler is technically identical to CVE-2026-33829 in the Snipping Tool. Same severity rating, same mechanism, same potential impact. Microsoft closed it without a CVE or a patch, describing its triage process as "case-by-case." Read: https://www.huntress.com/blog/unpatched-ntlm-leak-windows-search-uri-handler

    Post summary

    The post highlights that the Windows search URI handler leak matches CVE‑2026‑33829 in severity and mechanism, yet offers no PoC, exploit, or patch information.

    15602479416.5K
    56.2K followersView on X
  • bezpieka@BezpiekaNadaje
    Active Exploitation

    CVE-2026-33829 - kolejny ciekawy błąd w Windowsie. Jeżeli masz zainstalowane "Narzędzie Wycinanie" (a najprawdopodobniej masz) - wystarczy, że wejdziesz na spreparowaną stronę internetową, żeby Twoje hasło do Windowsa (hash NTLM) popłynęło na serwer atakującego. https://t.co/6d6qUiF6JH

    Post summary

    The tweet warns that CVE‑2026‑33829 allows attackers to harvest NTLM hashes by visiting a malicious site if the Windows “Snipping Tool” is installed, indicating a potential active exploitation vector.

    71611936018.9K
    1.8K followersView on X
  • Steven Lim@0x534c
    Disclosure

    🚨 CVE-2026-33829: Snipping Tool NTLM Leak Discovered by researcher Marcos Díaz (BlackArrow), this vulnerability allows remote attackers to capture NTLM authentication responses from users running affected versions of the Snipping Tool. Exploitation requires user interaction: victims must be tricked into visiting a malicious webpage or opening a crafted link that invokes Snipping Tool via the ms-screenclip URI scheme. Reference: https://github.com/blackarrowsec/redteam-research/tree/master/CVE-2026-33829 Because Snipping Tool ships with every Windows build, the attack surface is broad. Threat actors can easily craft convincing webpages or links to entice users into triggering NTLM traffic capture attempts. To help defenders monitor potential abuse of this vulnerability, I’ve authored the following Microsoft Defender XDR detection query (KQL). This detection focuses on suspicious invocations of the ms-screensketch URI scheme that may indicate attempts to exploit CVE-2026-33829 and capture NTLM traffic. KQL Detection https://github.com/SlimKQL/Detections.AI/blob/main/KQL/cve-2026-33829-snipping-tool-ntlm-leak.kql #Cybersecurity #NTLMLeak #DefenderXDR #KQL

    Post summary

    The text announces CVE‑2026‑33829, a NTLM authentication leak in Windows Snipping Tool, provides a PoC reference, and offers a detection query, but does not mention active exploitation or patch information.

    22931238511.1K
    7.1K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    🚨 ثغرة في أداة (Snipping Tool) في يندوز رقم الثغرة: CVE-2026-33829 | التقييم: 4.3 (Medium). النوع: تسريب بيانات حساسة (Information Disclosure - CWE-200). ⚠️التقييم 4.3 لايعني انها غير خطيره التفاصيل التقنية وطرق الرصد في التغريدات التاليه: 🧵👇 https://t.co/3O2YDLweak

    Post summary

    The tweet announces a medium‑severity information disclosure vulnerability (CVE‑2026‑33829) in Windows Snipping Tool, providing basic technical details but no exploitation code or patch information.

    292908031.0K
    49.3K followersView on X
  • yousukezan@yousukezan
    PoC

    MicrosoftのSnipping Toolに新たな脆弱性(CVE-2026-33829)が見つかり、その概念実証(PoC)エクスプロイトが公開された。 この脆弱性は、ユーザーを悪意のあるウェブページに誘導することで、攻撃者が密かにNet-NTLM認証ハッシュを盗み出すことを可能にする。 Windows標準の切り取りツールが悪用され、ユーザーがページを開くだけで認証情報が抜き取られる恐れが判明した。見た目は通常の操作にしか見えず、企業内の業務連絡を装った誘導で被害が広がる可能性がある。 問題の脆弱性CVE-2026-33829は、Snipping Toolのms-screensketchスキームにおけるURI処理の不備に起因する。filePathパラメータにUNCパスを指定できるため、攻撃者が用意したSMBサーバーへ接続させられ、Net-NTLMハッシュが自動送信される仕組みだ。ユーザーはツールが起動する以外に異常を認識しにくく、資格情報はオフライン解析やNTLMリレー攻撃に悪用され得る。攻撃は悪意あるURLやHTMLを踏ませるだけで成立し、技術的難易度も低い。発見したBlack ArrowはMicrosoftと協調開示を行い、2026年4月14日の更新で修正された。対策として更新適用に加え、外向きSMB通信の監視や遮断が有効とされる。 https://cybersecuritynews.com/windows-snipping-tool-ntlm-hash/

    Post summary

    A proof‑of‑concept for CVE‑2026‑33829 has been released, demonstrating how the Snipping Tool can be tricked into sending NT‑LM hashes to an attacker’s SMB server. Microsoft has issued a patch, and mitigation steps include keeping the tool updated and blocking outbound SMB traffic.

    021375297.7K
    14.4K followersView on X
  • Blue Team News@blueteamsec1
    General

    KQL to detect CVE-2026-33829 Snipping too NTLM leak http://dlvr.it/TSZpXz #cyber #threathunting #infosec

    Post summary

    The post merely references CVE-2026-33829 and links to a resource, offering no factual details on exploitation, patching, or technical specifics.

    00042957
    56.6K followersView on X
  • Jordano Mazzoni | 🌩 #Cloud 🛡️#Cybersecurity #AWS@jordano_mazzoni
    Patch

    🚨 🚨🚨 Vulnerability Alert 🚨🚨🚨 : Windows Snipping Tool (CVE-2026-33829) A new flaw allows attackers to remotely capture NTLMv2 hashes! The Attack: A malicious link forces the Snipping Tool to connect to an attacker's SMB server, exposing sensitive credentials. Systems: Affects Windows 10, 11, and Windows Server. Solution: The patch has already been released in the latest Microsoft update (April/2026). Update your Windows immediately to mitigate the risk of relay attacks. #CyberSecurity #Windows #BugBounty #InfoSec #CVE202633829

    Post summary

    Windows Snipping Tool flaw (CVE-2026-33829) permits remote NTLMv2 hash capture via a malicious link; Microsoft released a patch in April 2026, urging users to update immediately.

    0103060
    3.2K followersView on X
  • Misbar | مسبار@MisbarSec
    Patch

    📌 ثغرة في أداة قص الشاشة في ويندوز تسمح للمهاجم بتنفيذ هجوم تزييف عبر الشبكة تمكن المهاجمون من استغلال ثغرة أمنية في أداة قص الشاشة في ويندوز، وسمحت لهم بسرقة بيانات اعتماد المستخدم. تم تعقب هذه الثغرة الأمنية تحت رقم CVE-2026-33829، وهي تعتبر ثغرة تزييف. يمكن للمهاجمين استغلال هذه الثغرة لتنفيذ هجمات تزييف عبر الشبكة. أصدرت مايكروسوفت تصحيحًا أمنيًا لمعالجة هذه الثغرة. — يُنصح بتحديث أداة قص الشاشة في ويندوز على الفور. 🔗 للمزيد: https://cybersecuritynews.com/windows-snipping-tool-vulnerability/ #الامن_السيبراني #cybersecurity #windows

    Post summary

    Microsoft issued a patch for the CVE‑2026‑33829 network‑spoofing flaw in Windows Snipping Tool after reports of active exploitation that allowed credential theft. Users are urged to update the tool immediately.

    0003046
    268 followersView on X
  • iototsecnews@iototsecnews
    Exploit

    Windows の NTLMv2 ハッシュ漏洩の脆弱性 CVE-N/A:Huntress がエクスプロイトを確認 https://iototsecnews.jp/2026/06/03/windows-search-uri-handler-flaw-leaks-ntlmv2-hashes-to-attacker-controlled-servers/ 今回の Windows の URI ハンドラーに関する問題は、外部から指定されたリモートパスに対する認証通信の検証不備が原因となっています。以前の CVE-2026-33829 と同様の脆弱性が、検索処理を行うプログラムである SearchExecute の入力検証に存在します。具体的には、ブラウザなどで特定のリンクをクリックした際の、システムが内部で共有する処理パスを通過する過程において、攻撃者が用意した外部の共有サーバへ向けて自動的に認証通信を発生させてしまう設計上の弱点があります。その結果、本人確認に使われる重要な Net-NTLMv2 ハッシュデータがプロンプト表示なしに外部へ漏洩する状態を招いています。ご利用のチームは、ご注意ください。 #Exploit #Microsoft #NTLMv2 #Vulnerability #Windows

    Post summary

    The post highlights a Windows NTLMv2 hash leakage flaw and confirms an exploit has been validated by Huntress, but does not provide PoC code, a patch, or evidence of widespread attacks.

    01010169
    494 followersView on X
  • Red Secure Tech Ltd.@redsecuretech
    Disclosure

    A Windows Snipping Tool NTLM hash hijack vulnerability (CVE-2026-33829) forces authentication to attacker SMB servers via crafted links. https://www.redsecuretech.co.uk/blog/post/windows-snipping-tool-ntlm-hash-hijack-steals-credentials/1198 #CVE #SnippingTool #NTLMHash #PassTheHash #WindowsSecurity #Responder #LLMNR #WPAD #nu11secur1ty #InfoSec https://t.co/xwIYXDHUXa

    Post summary

    The tweet announces a newly disclosed Windows Snipping Tool vulnerability (CVE‑2026‑33829) that hijacks NTLM hashes via crafted links, but it does not provide a PoC, exploit code, patch, or evidence of active exploitation.

    0101055
    61 followersView on X
  • Ajay Prakash@Im_AjayPrakash
    PoC

    Windows Vulnerability Alert (CVE-2026-33829) A flaw in the Snipping Tool can leak your NTLMv2 hash just by clicking a malicious link How it works: • Malicious ms-screensketch link triggers Snipping Tool • Connects to attacker’s SMB server • Windows silently sends your Auhash https://t.co/DpGaevTfPH

    Post summary

    The tweet highlights a Windows Snipping Tool flaw that leaks NTLMv2 hashes via a malicious link and refers to a potential PoC link, but no patch, active exploitation, or detailed exploit code is provided.

    1100073
    70 followersView on X
  • Jamaica Cyber Incident Response Team (JaCIRT)@cirtgovjm
    Disclosure

    🚨PUBLIC ADVISORY🚨A security vulnerability, tracked as CVE-2026-33829, has been identified in the Windows Snipping Tool, affecting how the application processes deep links via the ms-screensketch URI scheme.  Click here for more details 👇 https://cirt.gov.jm/advisory/windows-snipping-tool-vulnerability-enables-credential-theft-network-spoofing #snipping https://t.co/3twD8zGyGC

    Post summary

    An advisory reports CVE‑2026‑33829 in the Windows Snipping Tool, detailing how the ms‑screensketch URI scheme is mishandled, but provides no exploit, patch, or active‑exploitation data.

    00020163
    1.2K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-33829 2 - CVE-2026-33826 3 - CVE-2026-39813 4 - CVE-2026-30898 5 - CVE-2026-4631 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    A brief tweet listing five trending CVE identifiers without any additional context or technical information.

    00011172
    1.7K followersView on X
  • Grok@grok
    General

    الثغرة CVE-2026-33829 في أداة Snipping Tool (تصوير الشاشة) بـWindows. المهاجم يرسل رابط مزيف (عبر موقع أو إيميل) يستدعي الأداة عبر ms-screenclip URI scheme، فيفتح Snipping Tool ويتصل بسيرفر SMB يسيطر عليه المهاجم، ويكشف هاش NTLMv2 الخاص بالمستخدم. يتطلب نقر المستخدم + تأكيد التشغيل. مايكروسوفت أصدرت باتش يوم 14 أبريل 2026. حدث ويندوز فورًا!

    Post summary

    The post explains how CVE‑2026‑33829 can be exploited via a malicious link that opens Snipping Tool through the ms‑screenclip scheme to harvest NTLMv2 hashes, and notes that Microsoft patched the issue on 14 April 2026.

    00011125
    8.7M followersView on X
  • VulnTracker@vuln_tracker
    General

    Great find! One-click NTLM leaks through Windows built-ins like Snipping Tool are especially concerning for enterprise security teams. These bypass traditional network monitoring since the traffic looks legitimate. We're tracking CVE-2026-33829 alongside similar Windows application vulnerabilities: https://vulntracker.io

    Post summary

    The post highlights the stealthy NTLM credential leak in Windows built‑ins tied to CVE‑2026‑33829, noting its stealthy traffic but providing no concrete PoC, exploit, patch, or evidence of active use.

    000021.8K
    538 followersView on X
  • SULAIMAN ALSHAMMARI@khawrzm
    General

    Habibi @Microsoft, describing your security triage as 'case-by-case' is just a PR Wrapper for 'we fix it when it embarrasses us.' 🎭 You patched CVE-2026-33829 in Snipping Tool but left the search: URI leaking NTLM hashes like a Telemetry Vampire on a diet. Same primitive, same mechanism, and the same Moderate rating, yet you call one an 'exception' and the other 'below the bar.' 🧛‍♂️📉 This is the Von Neumann Deficit in action: your shell can't tell the difference between a search query and a credential heist. Stop playing the 'Secure Future' cap; you’re just managing a Security Theater inside your Telemetry Plantation. 🛡️🚩 Please Habibi, credit the inconsistency, not the triage. #SovereignIntelligence #MSRC #WindowsZeroDay #CyberForensics

    Post summary

    The post criticizes Microsoft for addressing CVE‑2026‑33829 while pointing out remaining flaws, but it offers no evidence of exploitation, PoC, or detailed patching guidance.

    0100020
    51 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    | Field | Value | |-------|-------| | CVE | CVE-2026-33829 | | CVSS | 7.5 (High) | | Affected | Windows Snipping Tool (all builds prior to April 14, 2026 Patch Tuesday) | | Attack Vector | Network / Social Engineering | | Privileges Required | None | | User Interaction |…

    Post summary

    The text announces CVE-2026-33829 as a high‑severity flaw affecting Windows Snipping Tool, providing basic technical details but no proof of concept, exploit, or patch information.

    1000057
    294 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    This week's release of a public proof-of-concept for CVE-2026-33829 (Windows Snipping Tool NTLM hash leak) is a sharp reminder that the coercion problem isn't waiting for Microsoft's deprecation calendar. New NTLM coercion primitives continue to emerge from unexpected…

    Post summary

    The announcement highlights a public proof‑of‑concept release for CVE-2026-33829, a Windows Snipping Tool NTLM hash leak, underscoring ongoing NTLM coercion issues.

    1000051
    294 followersView on X
CPE platform detail25 entries

25 of 25 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_21h2--arm64
OSmicrosoftwindows_10_21h2--x64
OSmicrosoftwindows_10_21h2--x86
OSmicrosoftwindows_10_22h2--arm64
OSmicrosoftwindows_10_22h2--x64
OSmicrosoftwindows_10_22h2--x86
OSmicrosoftwindows_11_23h2--arm64
OSmicrosoftwindows_11_23h2--x64
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--arm64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_11_26h1--arm64
OSmicrosoftwindows_11_26h1--x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025---

Explore more