PT-2026-40234 · Microsoft · Netlogon+1

CVE-2026-41089

·

Published

2026-05-12

·

Updated

2026-07-20

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows Server versions prior to May 12, 2026
Description A stack-based buffer overflow exists in the Windows Netlogon service, which is used for user and service authentication in corporate networks. An unauthenticated remote attacker can exploit this by sending a specially crafted UDP packet to port 389 of a Windows Domain Controller. This flaw allows the attacker to execute arbitrary code with SYSTEM-level privileges, potentially leading to full Active Directory compromise, credential dumps, or ransomware deployment. Additionally, sending a malformed packet can cause the Domain Controller to reboot, resulting in a Denial of Service (DoS). The Belgium Cybersecurity Centre (CCB) has confirmed that this issue is being actively exploited in the wild.
Recommendations Deploy the May 2026 security updates on all domain controllers. Firewall-restrict RPC and Netlogon traffic. Monitor lsass.exe and the Netlogon service for anomalies. Enable Netlogon RPC sealing audit mode (Event ID 5827, 5828, and 5829).

Exploit

Fix

DoS

RCE

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-06756
CVE-2026-41089

Affected Products

Netlogon
Windows