Microsoft Windows Snipping Tool NTLM Information Disclosure Exploit

This module exploits an information disclosure vulnerability in Microsoft Windows Snipping Tool. A malicious web page invokes the ms-screensketch URI handler with an attacker-controlled UNC path. When the victim allows the browser to open Snipping Tool, the application connects to the SMB server and discloses the current user's Net-NTLM response. This exploit does not install an agent.
Exploit Platform
Product Name