# Windows Netlogon 0-Click RCE CVE-2026-41089 — Active Exploitation in the Wild (Domain Controller Takeover)

> CVE-2026-41089 is a critical, pre-authentication (0-click) stack-based buffer overflow in the Windows Netlogon DC-locator service (MS-NRPC / CLDAP). A single crafted CLDAP request to UDP/389 of an Active Directory domain controller overflows a 528-byte stack buffer in BuildSamLogonResponse via the bytes-vs-WCHAR length confusion in NetpLogonPutUnicodeString. Confirmed impact is reliable unauthenticated denial of service (LSASS crash 0xc0000409, DC auto-reboot ~60s); Microsoft and downstream reporting rate it RCE/CVSS 9.8 with potential SYSTEM-level code execution and full domain takeover. Patched in Microsoft's May 2026 Patch Tuesday and under active exploitation in the wild as of 2026-06-01, with a dedicated CCB emergency-patch warning.

- **Published:** 2026-06-01T00:00:00Z
- **Last reviewed:** 2026-06-01T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0642
- **ID:** TL-2026-0642
- **Severity:** CRITICAL (CVSS 9.8)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 16 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-41089

## Description

CVE-2026-41089 is a critical pre-authentication memory-corruption vulnerability in the Windows Netlogon component, specifically the DC-locator (LDAP ping) response path served by the Netlogon Remote Protocol (MS-NRPC) on Active Directory domain controllers. The flaw is exploitable by any unauthenticated attacker with network reachability to a DC, requires no user interaction (0-click), and Microsoft rates it as remote code execution with a CVSS 3.1 base score of 9.8. Because the affected code runs inside LSASS as SYSTEM, successful code execution yields complete control of the domain controller and, by extension, the entire Active Directory forest.

Root cause: the helper NetpLogonPutUnicodeString performs a character-by-character Unicode copy bounded only by a maximum character count, with no parameter for the destination buffer's total remaining size. A maximum string length value that is supplied in bytes is interpreted/treated as WCHARs, effectively doubling the number of characters written. BuildSamLogonResponse serializes a DC-locator response into a fixed 528-byte stack buffer inside NlGetLocalPingResponse, calling NetpLogonPutUnicodeString three times — for the server/host name (0x24 / 36 chars), the requesting username (0x82 / 130 chars, attacker-influenced), and the domain name (0x20 / 32 chars). When the attacker supplies a long username and the DC's own forest/domain/host FQDN labels are long (combined ~50+ characters), the server-controlled DNS-compressed name data is written past the buffer boundary, corrupting the GS stack cookie (located immediately past the buffer) and the saved return address (~0x48/72 bytes beyond the buffer end).

Trigger and exploit chain: the vulnerability is reached without any RPC opnum — an attacker sends a single connectionless LDAP (CLDAP) SearchRequest to UDP port 389. The malicious filter sets DnsDomain to the target domain, supplies a User attribute of 100+ characters (130 reliably triggers), and sets NtVer=0x02000000 (bits 2-3 clear) to force the legacy non-EX response path through the vulnerable BuildSamLogonResponse rather than the hardened BuildSamLogonResponseEx. The call chain is ntdsai!LDAP_CONN::SearchRequest -> netlogon!NlGetLocalPingResponse -> BuildSamLogonResponse -> NetpLogonPutUnicodeString. CLDAP DC-locator pings are processed before any credential check, making the attack fully pre-authentication.

Impact reality vs. escalation: public technical analysis (Aretiq, 0patch) confirms a single packet reliably produces a STATUS_STACK_BUFFER_OVERRUN (exception 0xc0000409) crash of LSASS, after which the domain controller automatically reboots in roughly 60 seconds. A 63-character DNS hostname label was shown to generate ~51 bytes of overflow — enough to corrupt the stack cookie and the return address region. Reliable, fully attacker-controlled RCE is constrained because the bytes that spill past the buffer are the server's own DNS name data rather than attacker-chosen payload bytes, and the overflow zone needed for a controlled return address is difficult to reach. Nevertheless, Microsoft, the CCB, and in-the-wild reporting treat CVE-2026-41089 as an RCE/domain-takeover threat: even absent code execution, an attacker who can repeatedly crash and reboot every domain controller in a forest causes a domain-wide authentication outage (mass DoS), and any reliable code-execution refinement on a DC running as SYSTEM enables the full post-exploitation kill chain below.

Post-exploitation (worst-case, SYSTEM on a DC): with code execution on a domain controller an adversary can perform OS credential dumping from the NTDS.dit database and LSASS, replicate directory secrets via DCSync (DRSUAPI GetNCChanges) to extract the krbtgt hash, forge Golden Tickets for persistent domain-wide authentication, create or elevate domain administrator accounts, manipulate group memberships, register a rogue/shadow domain controller (DCShadow), disable security tooling and logging, move laterally to high-value hosts, and stage destructive or ransomware follow-on actions. Tooling consistent with this tradecraft includes Impacket (secretsdump, ntlmrelayx), Mimikatz, Cobalt Strike, Sliver, and Brute Ratel.

Affected and remediation posture: the issue affects Windows Server 2012 and all later supported versions configured as domain controllers, and 0patch additionally ships micropatches for out-of-support Server 2008 R2 / 2012 / 2012 R2. Microsoft fixed it in the May 2026 Patch Tuesday cumulative updates (KB5089549 on the analyzed build), which replace the unsafe copy with RtlStringCbCopyExW byte-count budgets behind Feature_404993339; the 0patch micropatch halves the maximum username string size (mov edx, 0x40) to neutralize the attacker-controllable input. Domain controllers should be patched first and on an emergency basis, and inbound CLDAP (UDP/389) from untrusted networks should be restricted while patching proceeds.

## MITRE ATT&CK

- T1590 Gather Victim Network Information
- T1190 Exploit Public-Facing Application
- T1203 Exploitation for Client Execution
- T1068 Exploitation for Privilege Escalation
- T1003 OS Credential Dumping
- T1558 Steal or Forge Kerberos Tickets
- T1136 Create Account
- T1207 Rogue Domain Controller
- T1098 Account Manipulation
- T1685 Disable or Modify Tools
- T1482 Domain Trust Discovery
- T1087 Account Discovery
- T1210 Exploitation of Remote Services
- T1550 Use Alternate Authentication Material
- T1071 Application Layer Protocol
- T1499 Endpoint Denial of Service
- T1529 System Shutdown/Reboot

## Sources

- [Windows Netlogon 0-Click RCE Vulnerability Now Actively Exploited In The Wild](https://cybersecuritynews.com/windows-netlogon-0-click-rce/)
- [CVE-2026-41089 — Microsoft Windows Netlogon BuildSamLogonResponse Stack-based Buffer Overflow RCE](https://aretiq.ai/research/vul260513-cve-2026-41089-microsoft-windows-netlogon-buildsamlogonresponse-stack-based-buffer-overflow-rce/)
- [Micropatches Released for Windows Netlogon Remote Code Execution Vulnerability (CVE-2026-41089)](https://malware.news/t/micropatches-released-for-windows-netlogon-remote-code-execution-vulnerability-cve-2026-41089/107332)
- [Microsoft Patches 138 Vulnerabilities, Including DNS and Netlogon RCE Flaws](https://thehackernews.com/2026/05/microsoft-patches-138-vulnerabilities.html)
- [Patch Tuesday May 2026: CVE Analysis and AI-Discovered Bugs](https://www.automox.com/blog/patch-fix-tuesday-may-2026)
- [CVE-2026-41089 Netlogon RCE: Why Windows Domain Controllers Must Patch First](https://windowsforum.com/threads/cve-2026-41089-netlogon-rce-why-windows-domain-controllers-must-patch-first.417861/)
- [Microsoft Security Update Guide — CVE-2026-41089 (Netlogon Remote Code Execution Vulnerability)](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41089)
- [NVD — CVE-2026-41089 Detail](https://nvd.nist.gov/vuln/detail/CVE-2026-41089)
- [Centre for Cybersecurity Belgium (CCB) — Warning: Critical Netlogon RCE in Windows domain controllers (CVE-2026-41089)](https://ccb.belgium.be/en/news/warning-critical-netlogon-rce-windows-domain-controllers)
- [MS-NRPC: Netlogon Remote Protocol — Microsoft Open Specifications](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-nrpc/)
- [MS-ADTS: LDAP Ping (DC Locator / CLDAP) — Microsoft Open Specifications](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-adts/)
- [Secura — Zerologon: Unauthenticated domain controller compromise (CVE-2020-1472) Technical Whitepaper](https://www.secura.com/whitepapers/zerologon-whitepaper)
- [MITRE ATT&CK — Exploit Public-Facing Application (T1190)](https://attack.mitre.org/techniques/T1190/)
- [MITRE ATT&CK — Endpoint Denial of Service: Application or System Exploitation (T1499.004)](https://attack.mitre.org/techniques/T1499/004/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0642
