CVE-2026-41089 – Critical Remote Code Execution in Windows Netlogon
- Critical remote code execution (RCE) in Windows Netlogon (CVSS 9.8)
- Unauthenticated attacker can gain SYSTEM on domain controllers via a single crafted UDP packet (zero‑click)
- A patch has been available since May 12 2026; many unpatched DCs are still being targeted
- Immediate actions: apply the Microsoft patch, verify deployment, block inbound Netlogon (UDP 389) from untrusted networks, monitor for LSASS crashes and abnormal Netlogon traffic
Overview
CVE-2026-41089 is a Critical stack‑based buffer overflow in the Windows Netlogon service. Threat intelligence reports confirm active exploitation in the wild, with dozens of exploitation attempts observed daily since early June 2026. The flaw enables an unauthenticated attacker to execute arbitrary code with SYSTEM privileges on any domain controller that runs a vulnerable version of Windows Server.
The vulnerability was publicly disclosed on May 12 2026, and Microsoft released a security update the same day. Despite the rapid release, many organizations have not yet applied the patch, leaving their domain controllers exposed to a zero‑click remote code execution (RCE) attack.
For real‑time signal data, see the CVE page.
Technical Details
- Root cause: A stack‑based buffer overflow (CWE‑121) in the Netlogon Remote Procedure Call (RPC) handling code. An attacker sends a malformed CLDAP (Connection‑less LDAP) request to UDP port 389, overflowing a 528‑byte buffer in the LSASS process.
- Impact: The overflow corrupts the stack, allowing control‑flow hijack and execution of attacker‑supplied shellcode. Because Netlogon runs under the SYSTEM account, the attacker gains full administrative rights on the compromised domain controller.
- Exploit characteristics:
- Unauthenticated – no credentials required.
- Zero‑click – a single crafted packet is sufficient; no user interaction needed.
- Network‑only – the attacker only needs network reachability to the target DC’s Netlogon service (UDP 389).
- Observed behavior: Successful exploitation typically crashes LSASS, causing the domain controller to reboot within ~60 seconds. Repeated attempts can lead to denial‑of‑service conditions.
Severity & Impact
| Metric | Value |
|---|---|
| CVSS | 9.8 (Critical) |
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CWE | CWE‑121 (Stack‑based buffer overflow) |
The CVSS vector reflects network‑only, low complexity, no privileges, and no user interaction, with high confidentiality, integrity, and availability impact.
Affected Products
The flaw impacts domain‑controller installations of the following Microsoft Windows Server releases:
- Windows Server 2012 (including R2)
- Windows Server 2016
- Windows Server 2019
- Windows Server 2022 (including 23H2)
- Windows Server 2025
For the complete list of affected versions and editions, see the CVE page.
Actionable Insights
- Patch the vulnerability immediately on all domain controllers. Verify the update via
Get-HotFix -Id KBxxxxxxor the Windows Update history. - Validate patch adoption across the environment: use configuration management tools (e.g., SCCM, WSUS) to generate compliance reports.
- Restrict Netlogon traffic: block inbound UDP 389 from any network segment that does not require domain‑controller communication. Example firewall rule:
iptables -A INPUT -p udp --dport 389 -j DROP
- Enable LSA protection and enforce Protected Process Light (PPL) for LSASS to mitigate exploitation of memory‑corruption bugs.
- Monitor for indicators of compromise (IOCs):
- Sudden LSASS crashes or domain‑controller reboots (Event ID 1014, 1015).
- Unusual spikes in UDP 389 traffic, especially from external IP ranges.
- Detection signatures for malformed Netlogon packets (available from major IDS/IPS vendors).
- Apply temporary mitigations if patching cannot be performed immediately: disable the Netlogon service on non‑domain‑joined servers, or enforce IP‑based access controls to limit exposure.
Remediation & Mitigation
- Patch – Install the Microsoft security update released on May 12 2026 (KBxxxxxx).
- Verify – Run
Get-HotFix -Id KBxxxxxxon each DC and confirm the patch status. - Network hardening – Add firewall rules to block inbound UDP 389 from untrusted networks.
- Enable LSA protection – Set
RunAsPPLfor LSASS via Group Policy or registry. - Detect & Respond – Deploy IDS signatures for the malformed Netlogon packet and configure alerts for LSASS restarts.
- Audit – Review domain‑controller logs for anomalous Netlogon activity and correlate with threat‑intel feeds.
Bottom Line
CVE-2026-41089 is a Critical zero‑click RCE flaw in Windows Netlogon that is being actively exploited. The vulnerability grants SYSTEM‑level code execution on domain controllers with a single unauthenticated packet. A Microsoft patch has been available since May 12 2026, yet many environments remain vulnerable. Immediate patching, network segmentation, and continuous monitoring are essential to mitigate the risk.
References
- Microsoft security advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41089
- VulnSocial CVE overview: https://vulnsocial.com/cve/CVE-2026-41089
#CVE #Critical #RCE #Microsoft #WindowsServer #CVE202641089
