CVE-2026-8993 PUBLISHED

Improper URL Handler Processing in D.Launcher 2 enables NTLM Credential Disclosure and SSRF attacks

Assigner: SK-CERT
Reserved: 19.05.2026 Published: 02.06.2026 Updated: 02.06.2026

D.Launcher 2 component of Slovak eID client ecosystem contains Improper URL Handler Processing vulnerability. Application registers multiple custom URL handlers that could be exploited to initiate full NTLM autentication or SMB connection to attacker infrastructure and to conduct SSRF (Server Side Request Forgery) attacks. User interaction is required as potential victim needs to open a specially crafted URL.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS Score: 6.5

Product Status

Vendor Ditec a.s.
Product D.Launcher 2
Versions Default: unaffected
  • affected from 0 to 2.0.7 (excl.)

Credits

  • Martin Orem from Binary House finder

References

Problem Types

  • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CWE
  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE
  • CWE-1395: Dependency on Vulnerable Third-Party Component CWE

Impacts

  • CAPEC-272 Protocol Manipulation
  • CAPEC-137 Parameter Injection
  • CAPEC-153 Input Data Manipulation