CTIPilot

Windows Shell protection mechanism failure → NTLM coercion / spoofing (CVSS 4.3, APT28 ITW, KEV deadline 2026-05-12)

cve · CVE-2026-32202 single-source

Coverage timeline
1
first 2026-05-08 → last 2026-05-10
Peak priority
notable
1 notable
Sources cited
1
1 hosts
Sections touched
1
trending-vulnerabilities
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
0
no mapped behavior yet

Story timeline

  1. 2026-05-08CVE-2026-32202, Windows Shell NTLM coercion, APT28 ITW (CVSS 4.3, CISA KEV deadline 2026-05-12)
    trending-vulnerabilities

Where this entity is cited

  • trending-vulnerabilities1

Source distribution

  • nvd.nist.gov1 (100%)

explore in graph

Entries about Windows Shell protection mechanism failure → NTLM coercion / spoofing (CVSS 4.3, APT28 ITW, KEV deadline 2026-05-12) (1)

2026-05-08 · view entry permalink →

NOTABLECVE-2026-32202exploited

CVE-2026-32202, Windows Shell NTLM coercion, APT28 ITW (CVSS 4.3, CISA KEV deadline 2026-05-12)

A crafted Windows Shell artefact (LNK shortcut) placed in a directory causes the victim host to initiate an outbound SMB authentication to an attacker-controlled server when the directory is opened, transmitting NetNTLM hashes. APT28 has weaponised this against EU government ministries. Despite the low NVD CVSS (4.3), KEV listing and state-actor ITW exploitation make this a priority-patch item. Apply April 2026 Windows cumulative updates. CISA KEV deadline: 2026-05-12.

A crafted Windows Shell artefact (LNK shortcut) placed in a directory causes the victim host to initiate an outbound SMB authentication to an attacker-controlled server when the directory is opened, transmitting NetNTLM hashes.

ctipilot v2 brief (migrated)
vulnerability08 May 05:00Zsingle-sourceOpen finding ↗