Windows Search URI Handler NTLMv2 Hash Leak (CVE-2026-33829) | MSSP Advisory

HighHigh Confidence
DateJune 3, 2026
CVECVE-2026-33829
CVSS Score4.3
Affectedwindows_10_1607, windows_10_1809, windows_10_21h2
Risk Assessment
Client Exposure:Medium
Briefing Priority:Scheduled
Barrier to Entry:Moderate
📋Executive Summary
Huntress researcher Andrew Schwartz disclosed an unpatched vulnerability in the Windows search: URI handler that leaks NTLMv2 hashes to an attacker-controlled SMB server. The attack requires only a single user click on a crafted link delivered via email or web page, after which Windows silently authenticates outbound to an attacker SMB share and surrenders the Net-NTLMv2 hash. Microsoft reviewed the disclosure and declined to patch it, rating it below their servicing threshold, leaving every unmitigated Windows endpoint exposed indefinitely.
⚠️Why It Matters for MSSPs
Your RMM agents, PSA connectors, and technician workstations all run on Windows, and a single phishing email to one of your own staff could hand an attacker a crackable or relayable hash with access to everything that technician touches across your client base. On the client side, you manage environments where end users click links in email constantly, and if a client gets compromised through a vector you knew about and said nothing, that is a contract conversation you do not want to have.
Recommended Action
Block outbound SMB on TCP/445 and TCP/139 at your firewall and on every managed endpoint policy within the next 24 hours, then push SMB signing enforcement across all client environments via Group Policy or your RMM, and send a direct client advisory naming NTLM hash theft via Windows search links as the active unpatched risk.
🔒
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
Get your first advisory free →
🏷️Threat Category
Vulnerability Disclosure

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.