Junglewise Threat Intelligence

CVE-2026-33829: Microsoft Windows Snipping Tool Information Disclosure via ms-screensketch URI

CVE-2026-33829 · Severity: medium · CVSS 4.3 · Published 2026-04-14

Technologies: Microsoft Windows Server 2012, Microsoft Windows 10, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

The Windows Snipping Tool, a built-in application for capturing and editing screenshots, contains a flaw that can be used to steal a user's login credentials. By tricking a user into clicking a specially crafted link or visiting a malicious website, an attacker can force the user's computer to attempt a connection to a remote server. This process automatically shares the user's encrypted password information (NTLM hashes), which the attacker can then capture and attempt to crack or reuse to gain unauthorized access to the network.

Technical details

The Windows Snipping Tool fails to properly validate input for the 'ms-screensketch' URI scheme. Specifically, the 'filePath' parameter within this deep link can be manipulated to point to a remote SMB share (e.g., \\\\attacker-server\\file.png). When a victim clicks a link using this scheme, the Snipping Tool attempts to retrieve the file, triggering an automatic NTLM authentication request. This allows a remote, unauthenticated attacker to capture the victim's Net-NTLM hashes. Exploitation requires user interaction, such as clicking a link on a malicious webpage or in an email. Microsoft released patches for this vulnerability on April 14, 2026.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 22H3, 23H2, 24H2, 25H2, 26H1
  • Microsoft Windows Server 2012 R2

Timeline

  • 2026-03-23: disclosed: Vulnerability reported to Microsoft by BlackArrow.
  • 2026-04-14: patched: Microsoft released security updates.
  • 2026-04-14: advisory: Coordinated public release of the advisory.

References

Related threats