PT-2026-32887 · Microsoft · Snipping Tool+1
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Windows Snipping Tool (affected versions not specified)
Description
An information disclosure issue exists in the Windows Snipping Tool that allows remote attackers to capture NTLM authentication responses from users. This occurs when a victim is tricked into visiting a malicious webpage or opening a crafted link that invokes the Snipping Tool via the
ms-screenclip or ms-screensketch URI schemes. The flaw enables the attacker to perform spoofing attacks over a network by capturing sensitive authentication hashes.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Snipping Tool
Windows