PT-2026-40234 · Microsoft · Netlogon+1
Published
2026-05-12
·
Updated
2026-06-02
·
CVE-2026-41089
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Windows Server versions prior to May 12, 2026
Description
A stack-based buffer overflow exists in the Windows Netlogon service, specifically within the MS-NRPC handler. This flaw allows an unauthenticated remote attacker to execute arbitrary code with SYSTEM-level privileges on servers configured as domain controllers. The issue is triggered by sending a specially crafted Netlogon RPC packet over TCP port 445 or a crafted UDP packet to the CLDAP DC-locator port (UDP/389), which causes memory corruption in the
lsass.exe process. This can lead to a system reboot or full remote code execution. The Center for Cybersecurity Belgium (CCB) has confirmed that this issue is being actively exploited in the wild.Recommendations
Apply the Microsoft security updates released on May 12, 2026.
Firewall-restrict RPC and Netlogon traffic to minimize exposure.
Monitor the
lsass.exe process and Netlogon service for anomalies.
Monitor for malformed UDP traffic directed at port 389 on domain controllers.Exploit
Fix
RCE
DoS
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netlogon
Windows