Threat reportVulnerabilityTL-2026-0642
Windows Netlogon 0-Click RCE CVE-2026-41089 — Active Exploitation in the Wild (Domain Controller Takeover)
Windows Netlogon 0-Click RCE CVE-2026-41089 (TL-2026-0642) is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-06-01. It has no confirmed attribution, affects Microsoft Windows Server 2012 (Domain Controller), references 1 CVE (CVE-2026-41089), maps to 17 MITRE ATT&CK techniques (T1003, T1068, T1071), and is covered by 9 detection rules and 16 indicators of compromise.
- CVSS
- 9.8/10Critical
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 17MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 16Indicators of compromise
Key facts for TL-2026-0642
- Threat ID
- TL-2026-0642
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- government, financial, healthcare, technology, education, energy, manufacturing, defense, telecommunications
- Target regions
- North America, Europe, Asia-Pacific, Global
- Detection rules
- 9
- Indicators of compromise
- 16
Malware and tooling in Windows Netlogon 0-Click RCE CVE-2026-41089
Malware and tooling: Brute Ratel C4 - S1063, Cobalt Strike, Impacket - S0357, Mimikatz
How Windows Netlogon 0-Click RCE CVE-2026-41089 works
CVE-2026-41089 is a critical, pre-authentication (0-click) stack-based buffer overflow in the Windows Netlogon DC-locator service (MS-NRPC / CLDAP). A single crafted CLDAP request to UDP/389 of an Active Directory domain controller overflows a 528-byte stack buffer in BuildSamLogonResponse via the bytes-vs-WCHAR length confusion in NetpLogonPutUnicodeString. Confirmed impact is reliable unauthenticated denial of service (LSASS crash 0xc0000409, DC auto-reboot ~60s); Microsoft and downstream reporting rate it RCE/CVSS 9.8 with potential SYSTEM-level code execution and full domain takeover. Patched in Microsoft's May 2026 Patch Tuesday and under active exploitation in the wild as of 2026-06-01, with a dedicated CCB emergency-patch warning.
CVE-2026-41089 is a critical pre-authentication memory-corruption vulnerability in the Windows Netlogon component, specifically the DC-locator (LDAP ping) response path served by the Netlogon Remote Protocol (MS-NRPC) on Active Directory domain controllers. The flaw is exploitable by any unauthenticated attacker with network reachability to a DC, requires no user interaction (0-click), and Microsoft rates it as remote code execution with a CVSS 3.1 base score of 9.8. Because the affected code runs inside LSASS as SYSTEM, successful code execution yields complete control of the domain controller and, by extension, the entire Active Directory forest.
Root cause: the helper NetpLogonPutUnicodeString performs a character-by-character Unicode copy bounded only by a maximum character count, with no parameter for the destination buffer's total remaining size. A maximum string length value that is supplied in bytes is interpreted/treated as WCHARs, effectively doubling the number of characters written. BuildSamLogonResponse serializes a DC-locator response into a fixed 528-byte stack buffer inside NlGetLocalPingResponse, calling NetpLogonPutUnicodeString three times — for the server/host name (0x24 / 36 chars), the requesting username (0x82 / 130 chars, attacker-influenced), and the domain name (0x20 / 32 chars). When the attacker supplies a long username and the DC's own forest/domain/host FQDN labels are long (combined ~50+ characters), the server-controlled DNS-compressed name data is written past the buffer boundary, corrupting the GS stack cookie (located immediately past the buffer) and the saved return address (~0x48/72 bytes beyond the buffer end).
Trigger and exploit chain: the vulnerability is reached without any RPC opnum — an attacker sends a single connectionless LDAP (CLDAP) SearchRequest to UDP port 389. The malicious filter sets DnsDomain to the target domain, supplies a User attribute of 100+ characters (130 reliably triggers), and sets NtVer=0x02000000 (bits 2-3 clear) to force the legacy non-EX response path through the vulnerable BuildSamLogonResponse rather than the hardened BuildSamLogonResponseEx. The call chain is ntdsai!LDAP_CONN::SearchRequest -> netlogon!NlGetLocalPingResponse -> BuildSamLogonResponse -> NetpLogonPutUnicodeString. CLDAP DC-locator pings are processed before any credential check, making the attack fully pre-authentication.
Impact reality vs. escalation: public technical analysis (Aretiq, 0patch) confirms a single packet reliably produces a STATUS_STACK_BUFFER_OVERRUN (exception 0xc0000409) crash of LSASS, after which the domain controller automatically reboots in roughly 60 seconds. A 63-character DNS hostname label was shown to generate ~51 bytes of overflow — enough to corrupt the stack cookie and the return address region. Reliable, fully attacker-controlled RCE is constrained because the bytes that spill past the buffer are the server's own DNS name data rather than attacker-chosen payload bytes, and the overflow zone needed for a controlled return address is difficult to reach. Nevertheless, Microsoft, the CCB, and in-the-wild reporting treat CVE-2026-41089 as an RCE/domain-takeover threat: even absent code execution, an attacker who can repeatedly crash and reboot every domain controller in a forest causes a domain-wide authentication outage (mass DoS), and any reliable code-execution refinement on a DC running as SYSTEM enables the full post-exploitation kill chain below.
Post-exploitation (worst-case, SYSTEM on a DC): with code execution on a domain controller an adversary can perform OS credential dumping from the NTDS.dit database and LSASS, replicate directory secrets via DCSync (DRSUAPI GetNCChanges) to extract the krbtgt hash, forge Golden Tickets for persistent domain-wide authentication, create or elevate domain administrator accounts, manipulate group memberships, register a rogue/shadow domain controller (DCShadow), disable security tooling and logging, move laterally to high-value hosts, and stage destructive or ransomware follow-on actions. Tooling consistent with this tradecraft includes Impacket (secretsdump, ntlmrelayx), Mimikatz, Cobalt Strike, Sliver, and Brute Ratel.
Affected and remediation posture: the issue affects Windows Server 2012 and all later supported versions configured as domain controllers, and 0patch additionally ships micropatches for out-of-support Server 2008 R2 / 2012 / 2012 R2. Microsoft fixed it in the May 2026 Patch Tuesday cumulative updates (KB5089549 on the analyzed build), which replace the unsafe copy with RtlStringCbCopyExW byte-count budgets behind Feature_404993339; the 0patch micropatch halves the maximum username string size (mov edx, 0x40) to neutralize the attacker-controllable input. Domain controllers should be patched first and on an emergency basis, and inbound CLDAP (UDP/389) from untrusted networks should be restricted while patching proceeds.
MITRE ATT&CK techniques used in TL-2026-0642
Credential Access
T1003 OS Credential Dumping; T1558 Steal or Forge Kerberos Tickets
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Command and Control
T1071 Application Layer Protocol
Discovery
T1087 Account Discovery; T1482 Domain Trust Discovery
Persistence
T1098 Account Manipulation; T1136 Create Account
Initial Access
T1190 Exploit Public-Facing Application
Execution
T1203 Exploitation for Client Execution
defense-impairment
T1207 Rogue Domain Controller; T1685 Disable or Modify Tools
Lateral Movement
T1210 Exploitation of Remote Services; T1550 Use Alternate Authentication Material
Impact
T1499 Endpoint Denial of Service; T1529 System Shutdown/Reboot
Reconnaissance
Affected products and versions in Windows Netlogon 0-Click RCE CVE-2026-41089
- Microsoft — Windows Server 2012 (Domain Controller)
Vulnerable versions: 2012; 2012 R2
Fixed in: May 2026 cumulative update (out-of-support: 0patch micropatch) - Microsoft — Windows Server 2016 (Domain Controller)
Vulnerable versions: 2016
Fixed in: May 2026 cumulative update - Microsoft — Windows Server 2019 (Domain Controller)
Vulnerable versions: 2019
Fixed in: May 2026 cumulative update - Microsoft — Windows Server 2022 (Domain Controller)
Vulnerable versions: 2022
Fixed in: May 2026 cumulative update (KB5089549) - Microsoft — Windows Server 2025 (Domain Controller)
Vulnerable versions: 2025
Fixed in: May 2026 cumulative update - Microsoft — Windows Server 2008 R2 (Domain Controller, out-of-support)
Vulnerable versions: 2008 R2 (ESU 1-4)
Fixed in: 0patch micropatch
Remediation for Windows Netlogon 0-Click RCE CVE-2026-41089
Patches
- Microsoft May 2026 Patch Tuesday cumulative update — KB5089549 (analyzed build) and per-OS equivalents; replaces unsafe copy with RtlStringCbCopyExW byte-count budgets (Feature_404993339)
- 0patch micropatch (mov edx, 0x40) for unsupported Windows Server 2008 R2 / 2012 / 2012 R2
Immediate actions
- Emergency-patch ALL domain controllers with the Microsoft May 2026 cumulative update (KB5089549 / per-OS equivalent) — prioritize DCs before any other systems
- For out-of-support DCs (Server 2008 R2 / 2012 / 2012 R2), deploy the 0patch micropatch that halves the maximum username string size until full patching is possible
- Restrict inbound CLDAP (UDP/389) to domain controllers so it is only reachable from trusted internal network segments; block it from untrusted/segmented/internet-facing paths
- Deploy IDS/IPS and EDR detection for CLDAP SearchRequests carrying a User attribute of 100+ characters with NtVer=0x02000000
- Alert immediately on LSASS crashes with exception 0xc0000409 (STATUS_STACK_BUFFER_OVERRUN) and on unexpected domain controller reboots
Workarounds
- Firewall domain controllers to permit CLDAP (UDP/389) only from trusted management/client subnets
- Apply 0patch micropatching where vendor patches cannot yet be deployed
- Temporarily increase DC redundancy / monitor availability to absorb DoS crash-reboot loops during the exposure window
Longer-term hardening
- Enforce Active Directory tiered administration and isolate the DC management plane (network segmentation, jump hosts)
- Deploy EDR with memory-corruption / stack-overflow behavioral detection on all domain controllers
- Implement assume-breach monitoring for DCSync (DRSUAPI GetNCChanges from non-DC hosts), Golden Ticket usage, and anomalous privileged account creation
- Rotate the krbtgt account password (twice) if domain controller compromise is suspected
- Establish DC patch SLAs that treat pre-auth Netlogon/LSASS flaws as top-tier emergency remediation
CVEs associated with Windows Netlogon 0-Click RCE CVE-2026-41089
Weaknesses (CWE) in Windows Netlogon 0-Click RCE CVE-2026-41089
Timeline of Windows Netlogon 0-Click RCE CVE-2026-41089
- CVE-2026-41089 assigned and rated Critical (CVSS 3.1 base 9.8) — unauthenticated, no user interaction, code execution on domain controllers.
- Microsoft discloses and patches CVE-2026-41089 in the May 2026 Patch Tuesday release (reported as 118-138 flaws / 16 critical across sources), via cumulative update KB5089549 and per-OS equivalents.
- Proof-of-concept demonstrated: a single CLDAP packet (130-char User attribute, NtVer=0x02000000, long DNS domain) crashes LSASS with exception 0xc0000409 and forces a DC reboot (~60s).
- Independent technical analysis published detailing the BuildSamLogonResponse 528-byte stack overflow via NetpLogonPutUnicodeString bytes-vs-WCHAR confusion, reached through a CLDAP SearchRequest on UDP/389.
- 0patch releases micropatches (mov edx, 0x40 — halving the maximum username string size) covering out-of-support Windows Server 2008 R2 / 2012 / 2012 R2 domain controllers.
- Threadlinqs Intelligence opens TL-2026-0642 to track the active-exploitation escalation of CVE-2026-41089 as a distinct threat (escalation of the patched status captured in TL-2026-0504).
- Center for Cybersecurity Belgium (CCB) issues a dedicated warning urging emergency patching of domain controllers as a top-tier remediation item.
- Active exploitation in the wild confirmed against unpatched domain controllers; risk profile escalates from patched-not-exploited to actively-exploited.
Sources cited for Windows Netlogon 0-Click RCE CVE-2026-41089
- Windows Netlogon 0-Click RCE Vulnerability Now Actively Exploited In The Wild
- CVE-2026-41089 — Microsoft Windows Netlogon BuildSamLogonResponse Stack-based Buffer Overflow RCE
- Micropatches Released for Windows Netlogon Remote Code Execution Vulnerability (CVE-2026-41089)
- Microsoft Patches 138 Vulnerabilities, Including DNS and Netlogon RCE Flaws
- Patch Tuesday May 2026: CVE Analysis and AI-Discovered Bugs
- CVE-2026-41089 Netlogon RCE: Why Windows Domain Controllers Must Patch First
- Microsoft Security Update Guide — CVE-2026-41089 (Netlogon Remote Code Execution Vulnerability)
- NVD — CVE-2026-41089 Detail
- Centre for Cybersecurity Belgium (CCB) — Warning: Critical Netlogon RCE in Windows domain controllers (CVE-2026-41089)
- [MS-NRPC]: Netlogon Remote Protocol — Microsoft Open Specifications
- [MS-ADTS]: LDAP Ping (DC Locator / CLDAP) — Microsoft Open Specifications
- Secura — Zerologon: Unauthenticated domain controller compromise (CVE-2020-1472) Technical Whitepaper
- MITRE ATT&CK — Exploit Public-Facing Application (T1190)
- MITRE ATT&CK — Endpoint Denial of Service: Application or System Exploitation (T1499.004)
Detection coverage for TL-2026-0642
As of 2026-06-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0642 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.