
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21249 is a Windows NTLM spoofing vulnerability caused by improper input validation in the parsing of searchConnector-ms files, allowing remote attackers to disclose NTLM responses in the context of the current user. It affects a broad range of Microsoft Windows versions including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2), Windows Server 2012/2012 R2, 2016, 2019, 2022, 2022 23H2, and 2025. The vulnerability was disclosed and patched on February 10, 2026, as part of Microsoft's Patch Tuesday release. It carries a CVSS v3.1 base score of 3.3 (Low) (Microsoft MSRC, ZDI Advisory).
The root cause is classified as CWE-73 (External Control of File Name or Path), where insufficient input validation during the parsing of searchConnector-ms files allows an attacker to influence file or path resolution in a way that triggers NTLM authentication. An attacker can craft a malicious searchConnector-ms file or host a malicious web page that, when opened or visited by a target user, causes Windows to initiate an NTLM authentication request to an attacker-controlled server, leaking the user's NTLM hash. The attack vector is local (requiring the user to open a file or visit a page), and user interaction is required, limiting the attack surface. A proof-of-concept has been published by the Zero Day Initiative (ZDI Advisory, Feedly).
Successful exploitation results in the disclosure of the victim's NTLM response (hash) to an attacker-controlled server, compromising confidentiality with no direct impact on integrity or availability. The captured NTLM hash can be used in pass-the-hash attacks or offline cracking to impersonate the user, enabling lateral movement within a network and unauthorized access to systems and resources. The impact is scoped to the current user's credentials and does not directly escalate privileges on the local system (ZDI Advisory, Feedly).
searchConnector-ms XML file that references an attacker-controlled UNC path (e.g., \\attacker-server\share) in a way that triggers NTLM authentication when parsed by Windows..searchConnector-ms files in user download directories, email attachments, or shared drives.explorer.exe, SearchProtocolHost.exe) initiating outbound network connections to external addresses.Microsoft released patches on February 10, 2026, addressing this vulnerability across all affected Windows versions. Patched build versions include: Windows 10 1607 (10.0.14393.8868), Windows 10 1809 (10.0.17763.8389), Windows 10 21H2 (10.0.19044.6937), Windows 10 22H2 (10.0.19045.6937), Windows 11 23H2 (10.0.22631.6649), Windows 11 24H2 (10.0.26100.7781), Windows 11 25H2 (10.0.26200.7781), Windows Server 2022 (10.0.20348.4711), Windows Server 2022 23H2 (10.0.25398.2149), and Windows Server 2025 (10.0.26100.32313). As workarounds, administrators should consider blocking outbound NTLM authentication to external servers via Group Policy, enforcing Kerberos authentication in domain environments, and educating users about the risks of opening files from untrusted sources (Microsoft MSRC, Feedly).
The vulnerability was covered as part of broader February 2026 Patch Tuesday reporting by multiple security outlets including BleepingComputer, Qualys, Rapid7, and Sophos, though it received less individual attention due to its low CVSS score compared to other zero-days patched in the same cycle. The Zero Day Initiative published a dedicated advisory (ZDI-26-083) on February 12, 2026, providing additional technical context. Community discussion on WindowsForum highlighted the NTLM spoofing risk and recommended defender steps (BleepingComputer, ZDI Advisory, Qualys Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."