How the Windows Snipping Tool’s CVE-2026-33829 Opens the Door to NTLM Hash Theft

How the Windows Snipping Tool’s CVE-2026-33829 Opens the Door to NTLM Hash Theft

Microsoft patched a moderate-severity flaw in the Windows Snipping Tool in the April 14, 2026 security updates that could let attackers trick the application into leaking authentication material. Tracked as CVE-2026-33829 and reported by Blackarrow (Tarlogic), the issue stems from how Snipping Tool handles certain deep links and can result in an authenticated Server Message Block (SMB) connection to an