CVE-2026-41089: Windows Netlogon 0-Click RCE — Domain Controller Exploitation Deep Dive
Technical breakdown of the 0-click unauthenticated remote code execution flaw in Windows Netlogon allowing Domain Controller takeover.
CVE-2026-41089
Severity: CVSS 9.8
Target Component: Windows Server Active Directory Netlogon RPC
← Back to the June 4 Security Roundup
Overview
CVE-2026-41089 is a critical stack-based buffer overflow in the Windows Netlogon service (netlogon.dll) that allows an unauthenticated remote attacker to execute arbitrary code with SYSTEM privileges on any reachable domain controller. Active exploitation was confirmed on May 29, 2026, when Belgium's Centre for Cybersecurity (CCB) published a public warning and a proof-of-concept became available. CVSS v3.1 base score: 9.8 (Critical).
Affected Versions
- Windows Server 2019 (all builds prior to June 2026 Patch Tuesday)
- Windows Server 2022 (all builds prior to June 2026 Patch Tuesday)
- Windows Server 2025 (all builds prior to June 2026 Patch Tuesday)
- Windows Server 2016 (ESU – patch available)
Vulnerability Details
The flaw resides in the Netlogon Remote Protocol (MS-NRPC) message parser. When processing a specially crafted NetrServerAuthenticate3 or NetrLogonSamLogonWithFlags request, the service copies a caller-controlled credential blob into a fixed-size stack buffer without validating the supplied length. An attacker who controls the buffer content can overwrite the saved return address and redirect execution.
Because Netlogon listens on TCP/135 (DCE/RPC endpoint mapper) and dynamically assigned RPC ports, the attack surface is exposed on every domain controller that has not blocked inter-DC and client-to-DC RPC traffic at the network boundary.
Attack Chain
- Recon: Attacker enumerates domain controllers via LDAP (
_ldap._tcp.dc._msdcs.<domain>DNS SRV records) or direct port scanning on TCP 135+49152-65535. - Trigger: Attacker opens an unauthenticated DCE/RPC bind to the Netlogon interface (
{12345678-1234-ABCD-EF00-0123456789AB}) and sends a malformed credential blob (>512 bytes) inNetrServerAuthenticate3. - Stack smash: The overflowed return address is replaced with a ROP gadget in
netlogon.dll. Reliable exploitation uses a heap spray to land shellcode in a predictable location. - SYSTEM shell: The ROP chain calls
VirtualProtect+ executes staged shellcode. Because Netlogon runs as SYSTEM, the attacker immediately obtains a SYSTEM-level reverse shell. - Domain compromise: With SYSTEM on a DC, attacker runs
mimikatz lsadump::dcsyncto extract thekrbtgthash and forge Golden Tickets for persistent domain-wide access.
Indicators of Compromise (IOCs)
- Anomalous unauthenticated DCE/RPC binds to the Netlogon interface from external or untrusted subnets
- Windows Event ID 5820 (Netlogon – "Netlogon could not add the AuthZ RPC interface") in rapid succession
- Unusual
lsass.exechild processes or DLL injection intolsassfollowing Netlogon RPC activity - Network traffic: large (>512 byte)
NetrServerAuthenticate3request blobs to TCP 49152-65535 on DCs
Remediation
# 1. Apply the June 2026 Patch Tuesday updates on ALL domain controllers simultaneously.
# Partial patching leaves remaining DCs exploitable.
# 2. Verify patch is applied
Get-HotFix -Id KB5060842 # Windows Server 2022
Get-HotFix -Id KB5060840 # Windows Server 2019
Get-HotFix -Id KB5060836 # Windows Server 2025
# 3. Short-term: block unauthenticated RPC to DCs at the firewall
# Allow only trusted client subnets to reach TCP 135 + dynamic RPC ports on DCs
# Using Windows Firewall (run on each DC):
New-NetFirewallRule -DisplayName "Block Anon Netlogon RPC" `
-Direction Inbound -Protocol TCP -LocalPort 135 `
-RemoteAddress "0.0.0.0/0" -Action Block -Profile Domain
# 4. Enable Netlogon secure channel enforcement (if not already done post-Zerologon)
# Ensure FullSecureChannelProtection = 1 in the registry:
Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters" `
-Name "FullSecureChannelProtection" -Value 1 -Type DWord
← Back to the June 4 Security Roundup