Tracked as CVE-2026-33829, this spoofing vulnerability was officially patched during the April 14, 2026, security updates.
Discovered and reported by security researchers at Blackarrow (Tarlogic), the flaw highlights the ongoing risks associated with application URL handlers in Windows environments.
CVE-2026-33829 holds a CVSS 3.1 score of 4.3 and is classified as an exposure of sensitive information to unauthorized actors (CWE-200).
The vulnerability resides in how the Windows Snipping Tool processes deep links. Specifically, the application fails to validate input when handling the ms-screensketch URI schema properly.
According to the vulnerability disclosure provided by Microsoft and Blackarrow, an attacker can exploit this weakness to force an authenticated Server Message Block (SMB) connection to a remote, attacker-controlled server.
While the exploit requires user interaction, the attack complexity is considered low. Here is how the attack chain operates based on the released proof-of-concept:
ms-screensketch: edit parameter.Security experts warn that this vulnerability is highly adaptable for social engineering campaigns. An attacker could send a legitimate-looking webpage asking a user to crop a corporate wallpaper or edit a badge photo.
While the Snipping Tool opens normally on the user’s screen, making the request appear harmless, NTLM authentication occurs invisibly.
Although successful exploitation results in a loss of confidentiality, it does not allow the attacker to alter data (Integrity) or crash the system (Availability).
Microsoft notes that the exploit code maturity is currently unproven, and actual exploitation remains “Unlikely.” There are no reports of it being exploited in the wild.
The vulnerability, detailed on GitHub, impacts a wide range of Microsoft operating systems, including multiple versions of Windows 10, Windows 11, and Windows Server from 2012 through 2025.
To secure networks against CVE-2026-33829, organizations should implement the following mitigation strategies:
Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.
The post Windows Snipping Tool Vulnerability Allows Attacker to Perform Spoofing Over a Network appeared first on Cyber Security News.
Rick and Morty is returning for its ninth season this Sunday. We got the chance…
iBuypower is kicking off its Memorial Day Sale with tiered savings of up to $350…
Steven S. DeKnight's Spartacus: House of Ashur has reportedly been canceled at Starz after just…
Destiny players have taken to the Marathon Steam page to voice their frustrations with negative…
Although Final Fantasy 11 turns 24 this year, the MMORPG enjoyed a big boost in…
It’s a busy time for Warhammer 40,000 video games. The recent Warhammer Skulls showcase included…
This website uses cookies.