rootpwn

Advisories

Critical Windows Netlogon RCE Exploited in Wild – Immediate Patch Required

Microsoft’s latest advisory reveals CVE‑2026‑41089, a stack‑based buffer overflow in Netlogon that lets unauthenticated attackers run code with SYSTEM privileges on domain controllers. The flaw is already being leveraged in the field, affecting a wide range of Windows Server releases from 2012 to 2025. Rapid patching of all vulnerable servers is essential to stop attackers from hijacking domain infrastructure.

On May 12, 2026 Microsoft issued a critical advisory for a Netlogon vulnerability that lets attackers execute arbitrary code on domain controllers without authentication. The flaw, CVE‑2026‑41089, scores a 9.8 on CVSS and is a classic stack‑based buffer overflow.

How the Exploit Works

By sending specially crafted packets to the Netlogon service, an attacker can overflow a buffer and gain SYSTEM‑level access on any domain controller. Once compromised, the adversary can move laterally, exfiltrate data, or deploy ransomware across the entire domain.

Affected Windows Server Versions

  • Windows Server 2012 / 2012 R2
  • Windows Server 2016 (pre‑10.0.14393.9140)
  • Windows Server 2019 (pre‑10.0.17763.8755)
  • Windows Server 2022 (pre‑10.0.20348.5074)
  • Windows Server 2022 23H2 (pre‑10.0.25398.2330)
  • Windows Server 2025 (pre‑10.0.26100.32772)

Why This Matters Now

Threat actors are already exploiting the flaw in the wild, turning vulnerable domain controllers into entry points for broader attacks.

Mitigation Steps

  • Apply the latest Microsoft security update for the affected Windows Server version.
  • Verify that the Netlogon service is running the patched binaries (check for the presence of the updated security baseline).
  • Implement network segmentation to isolate domain controllers from untrusted traffic.
  • Deploy monitoring to detect anomalous Netlogon traffic or unexpected privilege escalations.

Bottom Line

If your environment runs any of the affected Windows Server releases, patch immediately. Delay could expose your entire domain to remote code execution and full control by malicious actors.

Netlogon CVE-2026-41089 Windows Server RCE Patch Domain Controller Threat Intel

← All news