Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A reported flaw in Windows Search can make a PC try to authenticate to an attacker-controlled SMB server after a user opens a crafted link. The reported exposure is a Net-NTLMv2 authentication response—not a plaintext password or direct remote code execution. Security coverage said the issue had no assigned CVE or patch when disclosed in June 2026; that is a dated status, not confirmation of its status today.

What is the Windows Search zero-day?

The report concerns Windows’ search: URI handler and a crafted link containing a crumb=location: parameter. According to CrowdSOC’s June 2, 2026 report on Huntress researcher Andrew Schwartz’s finding, a UNC path supplied as the location can lead Windows Search to initiate an SMB authentication exchange with a remote host. The host may capture the current user’s Net-NTLMv2 response.

CrowdSOC reported that search: and search-ms: are handled by the same SearchExecute COM class in ExplorerFrame.dll. Those implementation details, like the attack description, are secondary-source reporting; they should not be read as a Microsoft-assigned vulnerability identifier or as a technical confirmation from Microsoft.

What the attacker can get

A captured Net-NTLMv2 response is not the user’s plaintext password. Depending on the environment, an attacker may try to relay the authentication to a service that accepts NTLM, or attempt offline password cracking against the captured response. The reported behavior does not itself establish code execution on the victim’s PC.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall

What has been reported about affected systems

CrowdSOC said the behavior affected Windows 11 versions 23H2 and 25H2, including systems patched through the article’s June 2026 publication date. Treat that as the scope reported at that time, not a definitive list of currently supported or affected Windows versions.

How the reported attack works

  1. A user opens a crafted link. The report describes a link that invokes Windows’ Search URI handler and supplies a remote UNC location.
  2. Windows processes the location. The Search handler attempts to access the remote path over SMB.
  3. The remote host receives an authentication exchange. Windows may send a Net-NTLMv2 response for the current user, which the host can capture.
  4. The attacker may try to misuse the response. Relay or offline cracking attempts depend on the target environment and, for cracking, the password’s strength.

The cited reports do not establish confirmed in-the-wild exploitation of this specific finding. A link being opened is part of the described attack sequence; the report does not say that merely receiving one is enough.

Rank #2
Dell Latitude 3190 11.6" HD 2-in-1 Touchscreen Laptop Intel N5030 1.1Ghz 4GB Ram 128GB SSD Windows 11 Professional (Renewed)
  • 1.1 GHz (boost up to 2.4GHz) Intel Celeron N5030 Quad-Core
  • 4GB DDR4 System Memory; 128GB Solid State Drive
  • 11.6" HD (1366 x 768) Multi-Touch Display
  • Combo headphone/microphone jack - Noble Wedge Lock slot - HDMI; 2 USB 3.1 Gen 1
  • Windows 11 Pro

Is there a patch or CVE for the Search-handler report?

CrowdSOC and The Hacker News reported that Huntress disclosed the issue and Microsoft declined to service it. CrowdSOC said the report was made to Microsoft on April 15, 2026, the day after Microsoft’s April 14 update for a separate Snipping Tool issue. It reported that Microsoft considered the Search-handler case below its servicing bar, and that no CVE had been assigned and no fix was available as of the June 2026 article. These are publication-time reports; they do not establish Microsoft’s status as of October 2026.

CrowdSOC relayed a Microsoft response through Huntress saying that Important and Critical severity cases typically meet its servicing bar, while other factors can lead to exceptions. The article did not identify the Microsoft representative. The response explains the reported servicing decision; it is not a severity rating for the Search-handler issue.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Dell Latitude 5420 14" FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
  • 256 GB SSD of storage.
  • Multitasking is easy with 16GB of RAM
  • Equipped with a blazing fast Core i5 2.00 GHz processor.

How this differs from other Windows vulnerabilities

Issue Component and input CVE and reported status
Windows Search URI-handler finding Windows Search; search: handler with a reported crumb=location: UNC path. No CVE or fix reported by CrowdSOC and The Hacker News as of June 2026. No CVSS score for this finding is established in those reports.
Snipping Tool vulnerability Snipping Tool; ms-screensketch: handler and a filePath parameter. CVE-2026-33829; CrowdSOC reported that Microsoft patched it on April 14, 2026, and gave its CVSS v3.1 score as 4.3 (Moderate).
Windows Search Component listing A separately listed Windows Search Component information-disclosure issue involving weak authentication and local disclosure. CVE-2026-59135 appeared in an August 2026 listing. That separate listing is not evidence that the URI-handler finding received this CVE.

Installing the April 2026 update addresses the separate Snipping Tool CVE-2026-33829; it does not, based on the cited reporting, fix the Search-handler behavior described here.

How organizations can reduce exposure

CrowdSOC’s recommendations focus on limiting what a captured authentication exchange can reach and reducing reliance on NTLM. Validate policy changes against business requirements before deployment, especially where internal shares or older services depend on SMB or NTLM.

Rank #4
15.6 Inch Laptop Computer, N4020, 4GB DDR4 RAM, 128GB eMMC,with Windows 11
  • EFFORTLESS EVERYDAY PERFORMANCE: Powered by Intel Celeron N4020 processor and Windows 11 Home system, delivering reliable, low-power efficiency for daily tasks like document editing, email, online classes, and web browsing
  • 15.6-INCH FULL HD DISPLAY: Enjoy immersive visuals on the 15.6" FHD (1920x1080) anti-glare screen with micro-edge bezels. Delivers clear details and comfortable viewing for long study sessions, working on spreadsheets, and video playback
  • RESPONSIVE MULTITASKING & STORAGE: Built with 4GB LPDDR4 RAM and 128GB eMMC storage for smooth daily essential use. Expand your storage by up to 1TB via the integrated TF card slot to easily store movies, photos, and working files
  • ADVANCED CONNECTIVITY: Outfitted with 2x Full-Featured Type-C ports for data transfer, fast charging, and dual-monitor output, alongside 2x USB 3.2 Gen1 ports and a 3.5mm audio jack for complete peripheral compatibility
  • LIGHTWEIGHT & SILENT OPERATION: Slim and portable for effortless travel or commuting. Features a 1MP HD webcam for remote meetings, 38Wh battery with 45W Type-C fast charging, and a fanless silent design for peaceful work environments.
  • Restrict unnecessary outbound SMB. Block connections to arbitrary external hosts. Where workflows require SMB, allow only known destinations so the control does not disrupt required internal shares.
  • Enforce SMB signing. Signing can reduce the risk of relaying captured authentication to services that accept NTLM.
  • Audit NTLM before restricting it. Identify services and workflows that still rely on NTLM, then restrict or disable it where dependencies permit and Kerberos is available. A broad change without an inventory can break authentication-dependent services.
  • Monitor authentication and handler activity. Look for unexpected outbound SMB, NTLM authentication from unusual sources, and suspicious use of search:, search-ms:, or related URI handlers in mail, proxy, and endpoint telemetry.
  • Keep the separate Snipping Tool fix current. Apply the April 2026 Windows update for CVE-2026-33829, while treating it as distinct from the Search-handler report.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the reports establish—and what they do not

The June 2026 coverage describes a plausible credential-disclosure path involving a user-opened link, a Search URI, a remote UNC location, and SMB authentication. It reports a Microsoft servicing decision and a Windows 11 scope, but does not provide a Search-handler CVE, a patch, a prevalence estimate, or evidence of confirmed exploitation. Because the cited coverage is secondary and dated, it should be used to understand the reported mechanism—not as a live advisory or a guarantee about the current status of every Windows version.

Quick Recap

Bestseller No. 1
HP 14' HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Pink (Renewed)
HP 14" HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Pink (Renewed)
14" diagonal, 1366x768 resolution, HD BrightView LED, Glossy NON-TOUCH Display
$247.99
Bestseller No. 2
Dell Latitude 3190 11.6' HD 2-in-1 Touchscreen Laptop Intel N5030 1.1Ghz 4GB Ram 128GB SSD Windows 11 Professional (Renewed)
Dell Latitude 3190 11.6" HD 2-in-1 Touchscreen Laptop Intel N5030 1.1Ghz 4GB Ram 128GB SSD Windows 11 Professional (Renewed)
1.1 GHz (boost up to 2.4GHz) Intel Celeron N5030 Quad-Core; 4GB DDR4 System Memory; 128GB Solid State Drive
Bestseller No. 3
Dell Latitude 5420 14' FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
Dell Latitude 5420 14" FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
256 GB SSD of storage.; Multitasking is easy with 16GB of RAM; Equipped with a blazing fast Core i5 2.00 GHz processor.
$299.99
Best Value
15.6 Inch Win 11 Laptop Computer, N4020, 4GB DDR4 RAM, 128GB Storage
  • WINDOWS 11 | STABLE PERFORMANCE: Powered by Intel Celeron N4020 processor and Windows 11 system, this laptop delivers stable performance for everyday computing tasks. It supports web browsing, online learning, document editing, email communication, and basic office work with optimized power efficiency, providing a practical and reliable experience for essential daily use for daily use.
  • 15.6” FHD IPS DISPLAY: Features a 15.6-inch Full HD IPS display with narrow bezels, offering wider viewing angles and clearer image details compared to standard panels. The improved screen-to-body ratio enhances visual experience for study, reading, document work, and video playback, making it suitable for both productivity and entertainment use.
  • 4GB DDR4 + 128GB eMMC STORAGE: Equipped with 4GB DDR4 memory and 128GB eMMC storage for everyday basics such as browsing, documents, email, and online learning platforms. The built-in TF card slot supports storage expansion up to 1TB, giving you more flexibility for files, photos, videos, and daily documents. TF card not included.
  • CONNECTIVITY & PORTS: Includes 1× TF card slot, 2× USB 3.2 Gen1 ports, and 2× full-featured Type-C ports (USB 3.2 Gen1). The Type-C ports support data transfer, charging, and video output, enabling flexible connection with external devices such as monitors, storage, and peripherals for daily work and study use.
  • LIGHTWEIGHT DESIGN | ONLINE COMMUNICATION: Designed with a slim, portable profile, this laptop is easy to carry for school, commuting, and travel. A built-in 1MP front camera supports online classes, video meetings, remote communication, and everyday conferencing. The 3300mAh battery works with the low-power system design to support practical daily use, while thermal optimization helps maintain quieter operation during extended tasks.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.