Threat reportVulnerabilityTL-2026-0642

Windows Netlogon 0-Click RCE CVE-2026-41089 — Active Exploitation in the Wild (Domain Controller Takeover)

criticalACTIVE

Windows Netlogon 0-Click RCE CVE-2026-41089 (TL-2026-0642) is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-06-01. It has no confirmed attribution, affects Microsoft Windows Server 2012 (Domain Controller), references 1 CVE (CVE-2026-41089), maps to 17 MITRE ATT&CK techniques (T1003, T1068, T1071), and is covered by 9 detection rules and 16 indicators of compromise.

CVSS
9.8/10Critical
CVEs
1Referenced vulnerabilities
Techniques
17MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
16Indicators of compromise

Key facts for TL-2026-0642

Threat ID
TL-2026-0642
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
government, financial, healthcare, technology, education, energy, manufacturing, defense, telecommunications
Target regions
North America, Europe, Asia-Pacific, Global
Detection rules
9
Indicators of compromise
16

Malware and tooling in Windows Netlogon 0-Click RCE CVE-2026-41089

Malware and tooling: Brute Ratel C4 - S1063, Cobalt Strike, Impacket - S0357, Mimikatz

How Windows Netlogon 0-Click RCE CVE-2026-41089 works

CVE-2026-41089 is a critical, pre-authentication (0-click) stack-based buffer overflow in the Windows Netlogon DC-locator service (MS-NRPC / CLDAP). A single crafted CLDAP request to UDP/389 of an Active Directory domain controller overflows a 528-byte stack buffer in BuildSamLogonResponse via the bytes-vs-WCHAR length confusion in NetpLogonPutUnicodeString. Confirmed impact is reliable unauthenticated denial of service (LSASS crash 0xc0000409, DC auto-reboot ~60s); Microsoft and downstream reporting rate it RCE/CVSS 9.8 with potential SYSTEM-level code execution and full domain takeover. Patched in Microsoft's May 2026 Patch Tuesday and under active exploitation in the wild as of 2026-06-01, with a dedicated CCB emergency-patch warning.

CVE-2026-41089 is a critical pre-authentication memory-corruption vulnerability in the Windows Netlogon component, specifically the DC-locator (LDAP ping) response path served by the Netlogon Remote Protocol (MS-NRPC) on Active Directory domain controllers. The flaw is exploitable by any unauthenticated attacker with network reachability to a DC, requires no user interaction (0-click), and Microsoft rates it as remote code execution with a CVSS 3.1 base score of 9.8. Because the affected code runs inside LSASS as SYSTEM, successful code execution yields complete control of the domain controller and, by extension, the entire Active Directory forest.

Root cause: the helper NetpLogonPutUnicodeString performs a character-by-character Unicode copy bounded only by a maximum character count, with no parameter for the destination buffer's total remaining size. A maximum string length value that is supplied in bytes is interpreted/treated as WCHARs, effectively doubling the number of characters written. BuildSamLogonResponse serializes a DC-locator response into a fixed 528-byte stack buffer inside NlGetLocalPingResponse, calling NetpLogonPutUnicodeString three times — for the server/host name (0x24 / 36 chars), the requesting username (0x82 / 130 chars, attacker-influenced), and the domain name (0x20 / 32 chars). When the attacker supplies a long username and the DC's own forest/domain/host FQDN labels are long (combined ~50+ characters), the server-controlled DNS-compressed name data is written past the buffer boundary, corrupting the GS stack cookie (located immediately past the buffer) and the saved return address (~0x48/72 bytes beyond the buffer end).

Trigger and exploit chain: the vulnerability is reached without any RPC opnum — an attacker sends a single connectionless LDAP (CLDAP) SearchRequest to UDP port 389. The malicious filter sets DnsDomain to the target domain, supplies a User attribute of 100+ characters (130 reliably triggers), and sets NtVer=0x02000000 (bits 2-3 clear) to force the legacy non-EX response path through the vulnerable BuildSamLogonResponse rather than the hardened BuildSamLogonResponseEx. The call chain is ntdsai!LDAP_CONN::SearchRequest -> netlogon!NlGetLocalPingResponse -> BuildSamLogonResponse -> NetpLogonPutUnicodeString. CLDAP DC-locator pings are processed before any credential check, making the attack fully pre-authentication.

Impact reality vs. escalation: public technical analysis (Aretiq, 0patch) confirms a single packet reliably produces a STATUS_STACK_BUFFER_OVERRUN (exception 0xc0000409) crash of LSASS, after which the domain controller automatically reboots in roughly 60 seconds. A 63-character DNS hostname label was shown to generate ~51 bytes of overflow — enough to corrupt the stack cookie and the return address region. Reliable, fully attacker-controlled RCE is constrained because the bytes that spill past the buffer are the server's own DNS name data rather than attacker-chosen payload bytes, and the overflow zone needed for a controlled return address is difficult to reach. Nevertheless, Microsoft, the CCB, and in-the-wild reporting treat CVE-2026-41089 as an RCE/domain-takeover threat: even absent code execution, an attacker who can repeatedly crash and reboot every domain controller in a forest causes a domain-wide authentication outage (mass DoS), and any reliable code-execution refinement on a DC running as SYSTEM enables the full post-exploitation kill chain below.

Post-exploitation (worst-case, SYSTEM on a DC): with code execution on a domain controller an adversary can perform OS credential dumping from the NTDS.dit database and LSASS, replicate directory secrets via DCSync (DRSUAPI GetNCChanges) to extract the krbtgt hash, forge Golden Tickets for persistent domain-wide authentication, create or elevate domain administrator accounts, manipulate group memberships, register a rogue/shadow domain controller (DCShadow), disable security tooling and logging, move laterally to high-value hosts, and stage destructive or ransomware follow-on actions. Tooling consistent with this tradecraft includes Impacket (secretsdump, ntlmrelayx), Mimikatz, Cobalt Strike, Sliver, and Brute Ratel.

Affected and remediation posture: the issue affects Windows Server 2012 and all later supported versions configured as domain controllers, and 0patch additionally ships micropatches for out-of-support Server 2008 R2 / 2012 / 2012 R2. Microsoft fixed it in the May 2026 Patch Tuesday cumulative updates (KB5089549 on the analyzed build), which replace the unsafe copy with RtlStringCbCopyExW byte-count budgets behind Feature_404993339; the 0patch micropatch halves the maximum username string size (mov edx, 0x40) to neutralize the attacker-controllable input. Domain controllers should be patched first and on an emergency basis, and inbound CLDAP (UDP/389) from untrusted networks should be restricted while patching proceeds.

MITRE ATT&CK techniques used in TL-2026-0642

Credential Access

T1003 OS Credential Dumping; T1558 Steal or Forge Kerberos Tickets

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Command and Control

T1071 Application Layer Protocol

Discovery

T1087 Account Discovery; T1482 Domain Trust Discovery

Persistence

T1098 Account Manipulation; T1136 Create Account

Initial Access

T1190 Exploit Public-Facing Application

Execution

T1203 Exploitation for Client Execution

defense-impairment

T1207 Rogue Domain Controller; T1685 Disable or Modify Tools

Lateral Movement

T1210 Exploitation of Remote Services; T1550 Use Alternate Authentication Material

Impact

T1499 Endpoint Denial of Service; T1529 System Shutdown/Reboot

Reconnaissance

T1590 Gather Victim Network Information

Affected products and versions in Windows Netlogon 0-Click RCE CVE-2026-41089

  • Microsoft — Windows Server 2012 (Domain Controller)
    Vulnerable versions: 2012; 2012 R2
    Fixed in: May 2026 cumulative update (out-of-support: 0patch micropatch)
  • Microsoft — Windows Server 2016 (Domain Controller)
    Vulnerable versions: 2016
    Fixed in: May 2026 cumulative update
  • Microsoft — Windows Server 2019 (Domain Controller)
    Vulnerable versions: 2019
    Fixed in: May 2026 cumulative update
  • Microsoft — Windows Server 2022 (Domain Controller)
    Vulnerable versions: 2022
    Fixed in: May 2026 cumulative update (KB5089549)
  • Microsoft — Windows Server 2025 (Domain Controller)
    Vulnerable versions: 2025
    Fixed in: May 2026 cumulative update
  • Microsoft — Windows Server 2008 R2 (Domain Controller, out-of-support)
    Vulnerable versions: 2008 R2 (ESU 1-4)
    Fixed in: 0patch micropatch

Remediation for Windows Netlogon 0-Click RCE CVE-2026-41089

Patches

  • Microsoft May 2026 Patch Tuesday cumulative update — KB5089549 (analyzed build) and per-OS equivalents; replaces unsafe copy with RtlStringCbCopyExW byte-count budgets (Feature_404993339)
  • 0patch micropatch (mov edx, 0x40) for unsupported Windows Server 2008 R2 / 2012 / 2012 R2

Immediate actions

  • Emergency-patch ALL domain controllers with the Microsoft May 2026 cumulative update (KB5089549 / per-OS equivalent) — prioritize DCs before any other systems
  • For out-of-support DCs (Server 2008 R2 / 2012 / 2012 R2), deploy the 0patch micropatch that halves the maximum username string size until full patching is possible
  • Restrict inbound CLDAP (UDP/389) to domain controllers so it is only reachable from trusted internal network segments; block it from untrusted/segmented/internet-facing paths
  • Deploy IDS/IPS and EDR detection for CLDAP SearchRequests carrying a User attribute of 100+ characters with NtVer=0x02000000
  • Alert immediately on LSASS crashes with exception 0xc0000409 (STATUS_STACK_BUFFER_OVERRUN) and on unexpected domain controller reboots

Workarounds

  • Firewall domain controllers to permit CLDAP (UDP/389) only from trusted management/client subnets
  • Apply 0patch micropatching where vendor patches cannot yet be deployed
  • Temporarily increase DC redundancy / monitor availability to absorb DoS crash-reboot loops during the exposure window

Longer-term hardening

  • Enforce Active Directory tiered administration and isolate the DC management plane (network segmentation, jump hosts)
  • Deploy EDR with memory-corruption / stack-overflow behavioral detection on all domain controllers
  • Implement assume-breach monitoring for DCSync (DRSUAPI GetNCChanges from non-DC hosts), Golden Ticket usage, and anomalous privileged account creation
  • Rotate the krbtgt account password (twice) if domain controller compromise is suspected
  • Establish DC patch SLAs that treat pre-auth Netlogon/LSASS flaws as top-tier emergency remediation

CVEs associated with Windows Netlogon 0-Click RCE CVE-2026-41089

CVE-2026-41089

Weaknesses (CWE) in Windows Netlogon 0-Click RCE CVE-2026-41089

CWE-121, CWE-787, CWE-131, CWE-20

Timeline of Windows Netlogon 0-Click RCE CVE-2026-41089

  • CVE-2026-41089 assigned and rated Critical (CVSS 3.1 base 9.8) — unauthenticated, no user interaction, code execution on domain controllers.
  • Microsoft discloses and patches CVE-2026-41089 in the May 2026 Patch Tuesday release (reported as 118-138 flaws / 16 critical across sources), via cumulative update KB5089549 and per-OS equivalents.
  • Proof-of-concept demonstrated: a single CLDAP packet (130-char User attribute, NtVer=0x02000000, long DNS domain) crashes LSASS with exception 0xc0000409 and forces a DC reboot (~60s).
  • Independent technical analysis published detailing the BuildSamLogonResponse 528-byte stack overflow via NetpLogonPutUnicodeString bytes-vs-WCHAR confusion, reached through a CLDAP SearchRequest on UDP/389.
  • 0patch releases micropatches (mov edx, 0x40 — halving the maximum username string size) covering out-of-support Windows Server 2008 R2 / 2012 / 2012 R2 domain controllers.
  • Threadlinqs Intelligence opens TL-2026-0642 to track the active-exploitation escalation of CVE-2026-41089 as a distinct threat (escalation of the patched status captured in TL-2026-0504).
  • Center for Cybersecurity Belgium (CCB) issues a dedicated warning urging emergency patching of domain controllers as a top-tier remediation item.
  • Active exploitation in the wild confirmed against unpatched domain controllers; risk profile escalates from patched-not-exploited to actively-exploited.

Sources cited for Windows Netlogon 0-Click RCE CVE-2026-41089

Detection coverage for TL-2026-0642

As of 2026-06-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0642 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
16 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats