Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

Microsoft has formally declined to patch CVE-2026-33829, a vulnerability in the Windows ‘search:’ URI handler that allows attackers to capture NTLMv2 credential hashes by tricking users into clicking a malicious link. All supported Windows versions are affected, and no vendor-supplied fix is forthcoming, leaving every Windows enterprise environment dependent on compensating controls. The business risk is credential exposure leading to lateral movement, privilege escalation, and potential domain compromise, with no patch timeline to cite to auditors or the board.

Author

Tech Jacks Solutions