CVE-2026-21249
vulnerability analysis and mitigation

Overview

CVE-2026-21249 is a Windows NTLM spoofing vulnerability caused by improper input validation in the parsing of searchConnector-ms files, allowing remote attackers to disclose NTLM responses in the context of the current user. It affects a broad range of Microsoft Windows versions including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2), Windows Server 2012/2012 R2, 2016, 2019, 2022, 2022 23H2, and 2025. The vulnerability was disclosed and patched on February 10, 2026, as part of Microsoft's Patch Tuesday release. It carries a CVSS v3.1 base score of 3.3 (Low) (Microsoft MSRC, ZDI Advisory).

Technical details

The root cause is classified as CWE-73 (External Control of File Name or Path), where insufficient input validation during the parsing of searchConnector-ms files allows an attacker to influence file or path resolution in a way that triggers NTLM authentication. An attacker can craft a malicious searchConnector-ms file or host a malicious web page that, when opened or visited by a target user, causes Windows to initiate an NTLM authentication request to an attacker-controlled server, leaking the user's NTLM hash. The attack vector is local (requiring the user to open a file or visit a page), and user interaction is required, limiting the attack surface. A proof-of-concept has been published by the Zero Day Initiative (ZDI Advisory, Feedly).

Impact

Successful exploitation results in the disclosure of the victim's NTLM response (hash) to an attacker-controlled server, compromising confidentiality with no direct impact on integrity or availability. The captured NTLM hash can be used in pass-the-hash attacks or offline cracking to impersonate the user, enabling lateral movement within a network and unauthorized access to systems and resources. The impact is scoped to the current user's credentials and does not directly escalate privileges on the local system (ZDI Advisory, Feedly).

Exploitation steps

  1. Craft a malicious searchConnector-ms file: Create a specially crafted searchConnector-ms XML file that references an attacker-controlled UNC path (e.g., \\attacker-server\share) in a way that triggers NTLM authentication when parsed by Windows.
  2. Deliver the payload: Host the malicious file on a web page, send it via phishing email, or distribute it through a file share to lure the target user into opening it.
  3. Set up an NTLM capture server: Run a tool such as Responder or a custom SMB/HTTP listener on the attacker-controlled server to intercept incoming NTLM authentication requests.
  4. Wait for user interaction: When the target user opens the malicious file or visits the malicious page, Windows automatically attempts NTLM authentication to the attacker's server, sending the user's NTLM hash.
  5. Capture and leverage the NTLM hash: The attacker captures the NTLMv2 response and can use it for offline password cracking (e.g., with Hashcat) or relay it in a pass-the-hash/NTLM relay attack to authenticate to other systems in the network (ZDI Advisory, Feedly).

Indicators of compromise

  • Network: Unexpected outbound SMB (TCP 445) or HTTP/HTTPS connections from a workstation to an external or unknown IP address, particularly following a user opening a file or visiting a web page; NTLM authentication attempts to non-corporate servers.
  • File System: Presence of unexpected or unsolicited .searchConnector-ms files in user download directories, email attachments, or shared drives.
  • Logs: Windows Security Event Log entries (Event ID 4648 or 4624) showing NTLM logon attempts to unfamiliar or external hosts; network traffic logs showing SMB or WebDAV connections to external IPs shortly after file open events.
  • Process: Windows Explorer or search-related processes (explorer.exe, SearchProtocolHost.exe) initiating outbound network connections to external addresses.

Mitigation and workarounds

Microsoft released patches on February 10, 2026, addressing this vulnerability across all affected Windows versions. Patched build versions include: Windows 10 1607 (10.0.14393.8868), Windows 10 1809 (10.0.17763.8389), Windows 10 21H2 (10.0.19044.6937), Windows 10 22H2 (10.0.19045.6937), Windows 11 23H2 (10.0.22631.6649), Windows 11 24H2 (10.0.26100.7781), Windows 11 25H2 (10.0.26200.7781), Windows Server 2022 (10.0.20348.4711), Windows Server 2022 23H2 (10.0.25398.2149), and Windows Server 2025 (10.0.26100.32313). As workarounds, administrators should consider blocking outbound NTLM authentication to external servers via Group Policy, enforcing Kerberos authentication in domain environments, and educating users about the risks of opening files from untrusted sources (Microsoft MSRC, Feedly).

Community reactions

The vulnerability was covered as part of broader February 2026 Patch Tuesday reporting by multiple security outlets including BleepingComputer, Qualys, Rapid7, and Sophos, though it received less individual attention due to its low CVSS score compared to other zero-days patched in the same cycle. The Zero Day Initiative published a dedicated advisory (ZDI-26-083) on February 12, 2026, providing additional technical context. Community discussion on WindowsForum highlighted the NTLM spoofing risk and recommended defender steps (BleepingComputer, ZDI Advisory, Qualys Blog).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management