Windows search vulnerability exposes NTLM credentials

Huntress describes an unpatched Windows Search URI handler vulnerability that can be abused to leak NTLM authentication hashes to attacker-controlled servers with minimal user interaction. By leveraging the search-ms protocol, attackers can trick users into opening malicious search results that trigger outbound authentication requests, exposing credentials that may be used in relay or offline cracking attacks. The researchers note that the issue remains unpatched, making it another example of how legacy NTLM authentication continues to create credential theft risk in Windows environments.

What this means for your organisation

With no patch to install, this is a case where the organisation must manage the risk through configuration and monitoring instead. NTLM persists in many environments because legacy applications require it, and every such dependency is also an open door for relay attacks. What leaks is not a file but the user's identity, and it can be reused without anyone noticing.

Berigo recommends

  • Block outbound SMB traffic to the internet at the firewall so external authentication attempts do not complete.
  • Map where NTLM is still in use and plan the transition to Kerberos or modern authentication.
  • Enable signing and relay protection wherever the environment supports it.
  • Monitor for unusual authentication attempts and logins from accounts acting outside their normal pattern.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch