A newly disclosed issue in the Windows Search URI handler could let a crafted activation path disclose NTLMv2 hash material, showing how ordinary deep links can become security boundaries.
A Windows Search URI-handler flaw is being linked to NTLMv2 material leaking to attacker-controlled servers after a single click, showing how built-in convenience features can become authentication boundaries.