Exploit for CVE-2026-32202 in Windows Explorer for Sale
Dark Web2026-09-08, 09:18
For informational purposes only.
Vulnerability Type: Information Disclosure via NTLM Authentication Coercion
Vulnerable Versions: Windows 10/11/Windows Server 2012 and later without the April 2026 patch
Price: $6,500
The author is selling an exploit for the CVE-2026-32202 vulnerability. It is advertised as a zero-click exploit via a Windows Explorer vulnerability related to the processing of specially crafted LNK files: The user simply needs to open a folder containing a malicious shortcut; when Explorer attempts to display its icon or metadata, it automatically processes the embedded Control Panel object and may initiate an SMB connection to the attacker’s server, transmitting NTLM authentication credentials. In this case, clicking on the file itself is not required, and SmartScreen does not trigger, since the network call occurs at an earlier stage of the shortcut’s processing, even before it is actually launched.
It is worth noting that publicly available exploits exist for this vulnerability.
Vulnerabilities
Researchers
Vendors
Products