PT-2026-32887 · Microsoft · Snipping Tool+1

Marcos Díaz

·

Published

2026-04-14

·

Updated

2026-06-03

·

CVE-2026-33829

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Windows Snipping Tool (affected versions not specified)
Description An issue in the Windows Snipping Tool involves the exposure of sensitive information to unauthorized actors, which allows remote attackers to perform spoofing attacks over a network. Specifically, the application leaks NTLM (NT LAN Manager) authentication responses, which are hashes used for Windows authentication. Exploitation requires user interaction, such as tricking a victim into visiting a malicious webpage or opening a crafted link that invokes the Snipping Tool via the ms-screenclip or ms-screensketch URI schemes. This action causes the tool to connect to an attacker-controlled SMB (Server Message Block) server, leading Windows to silently send the user's NTLMv2 hash, which can then be cracked or relayed to gain unauthorized access to corporate networks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2026-05657
CVE-2026-33829

Affected Products

Snipping Tool
Windows