PT-2026-32854 · Microsoft · Windows Shell+1

·

CVE-2026-32202

·

Published

2026-04-14

·

Updated

2026-07-14

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Microsoft Windows (affected versions not specified)
Description A protection mechanism failure in the Windows Shell allows a remote unauthorized attacker to perform spoofing. The issue occurs when a malicious Windows shortcut or LNK path triggers an automatic SMB authentication attempt, which exposes the victim's Net-NTLMv2 hash for potential offline cracking or relay attacks. This flaw can be triggered without user interaction, such as when a user simply opens a folder containing a malicious shortcut. This issue has been actively exploited in the wild by APT28 (Fancy Bear) targeting Ukraine and EU nations as part of a larger exploit chain to steal credentials and download malicious code from remote servers.
Recommendations Apply the security updates released in April 2026.

Exploit

Fix

DoS

RCE

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-05493
CVE-2026-32202

Affected Products

Windows
Windows Shell