PT-2026-32854 · Microsoft · Windows Shell+1
Maor Dahan
·
Published
2026-04-14
·
Updated
2026-06-05
·
CVE-2026-32202
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows versions prior to April 2026
Description
A protection mechanism failure in the Windows Shell allows an unauthorized remote attacker to perform spoofing. The issue occurs because Windows Explorer automatically attempts to fetch icons via UNC paths, triggering an NTLM handshake. This allows a malicious Windows shortcut or LNK path to initiate an automatic SMB authentication attempt, exposing the victim's
Net-NTLMv2 hash for potential relay or offline cracking without any user interaction. This flaw has been actively exploited by APT28 (also known as Fancy Bear) in attacks targeting Ukraine and European nations.Recommendations
Update Microsoft Windows to the version released in April 2026.
Exploit
Fix
RCE
DoS
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows
Windows Shell