PT-2026-40234 · Microsoft · Netlogon+1
CVE-2026-41089
·
Published
2026-05-12
·
Updated
2026-07-20
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Windows Server versions prior to May 12, 2026
Description
A stack-based buffer overflow exists in the Windows Netlogon service, which is used for user and service authentication in corporate networks. An unauthenticated remote attacker can exploit this by sending a specially crafted UDP packet to port 389 of a Windows Domain Controller. This flaw allows the attacker to execute arbitrary code with SYSTEM-level privileges, potentially leading to full Active Directory compromise, credential dumps, or ransomware deployment. Additionally, sending a malformed packet can cause the Domain Controller to reboot, resulting in a Denial of Service (DoS). The Belgium Cybersecurity Centre (CCB) has confirmed that this issue is being actively exploited in the wild.
Recommendations
Deploy the May 2026 security updates on all domain controllers.
Firewall-restrict RPC and Netlogon traffic.
Monitor
lsass.exe and the Netlogon service for anomalies.
Enable Netlogon RPC sealing audit mode (Event ID 5827, 5828, and 5829).Exploit
Fix
DoS
RCE
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netlogon
Windows