XSS to NTLM Leak using MSQuery

By |2024-02-09T13:34:12-05:00February 9, 2024|Blog|

Recently, a paper regarding a new CVE was published by Varonis about multiple exploits to coerce Net-NTLM authentication. One of these methods abuses how explorer.exe handles search queries for files. Web browsers can open applications ...