Executive brief
The Windows Snipping Tool, a built-in application for capturing and editing screenshots, contains a flaw that can be used to steal a user's login credentials. By tricking a user into clicking a specially crafted link or visiting a malicious website, an attacker can force the user's computer to attempt a connection to a remote server. This process automatically shares the user's encrypted password information (NTLM hashes), which the attacker can then capture and attempt to crack or reuse to gain unauthorized access to the network.
Technical details
The Windows Snipping Tool fails to properly validate input for the 'ms-screensketch' URI scheme. Specifically, the 'filePath' parameter within this deep link can be manipulated to point to a remote SMB share (e.g., \\\\attacker-server\\file.png). When a victim clicks a link using this scheme, the Snipping Tool attempts to retrieve the file, triggering an automatic NTLM authentication request. This allows a remote, unauthenticated attacker to capture the victim's Net-NTLM hashes. Exploitation requires user interaction, such as clicking a link on a malicious webpage or in an email. Microsoft released patches for this vulnerability on April 14, 2026.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 22H3, 23H2, 24H2, 25H2, 26H1
- Microsoft Windows Server 2012 R2
Timeline
- 2026-03-23: disclosed: Vulnerability reported to Microsoft by BlackArrow.
- 2026-04-14: patched: Microsoft released security updates.
- 2026-04-14: advisory: Coordinated public release of the advisory.