Potential NTLM hash leak via MS Photos
Detects a potential NTLM hash disclosure via abuse of the ms-photos: URI scheme with a UNC path parameter. An attacker can craft a specially formatted link that, when opened, launches Microsoft Photos directly from a browser and triggers outbound authentication, potentially leaking NTLM credentials.
- Platform: Windows
- Severity: High
- MITRE Tactic: Credential Access
- MITRE Techniques: T1187