PT-2026-32854 · Microsoft · Windows Shell+1
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows (affected versions not specified)
Description
A protection mechanism failure in the Windows Shell allows a remote unauthorized attacker to perform spoofing. The issue occurs when a malicious Windows shortcut or LNK path triggers an automatic SMB authentication attempt, which exposes the victim's Net-NTLMv2 hash for potential offline cracking or relay attacks. This flaw can be triggered without user interaction, such as when a user simply opens a folder containing a malicious shortcut. This issue has been actively exploited in the wild by APT28 (Fancy Bear) targeting Ukraine and EU nations as part of a larger exploit chain to steal credentials and download malicious code from remote servers.
Recommendations
Apply the security updates released in April 2026.
Exploit
Fix
DoS
RCE
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows
Windows Shell