CVE-2026-41089: Windows Netlogon 0-Click RCE — Domain Controller Exploitation Deep Dive

Technical breakdown of the 0-click unauthenticated remote code execution flaw in Windows Netlogon allowing Domain Controller takeover.

CVE-2026-41089: Windows Netlogon 0-Click RCE — Domain Controller Exploitation Deep Dive
📌
Security Roundup Series: Week of June 4, 2026 • 4 min read deep dive
🚨
Threat Intelligence & Technical Specs: CVE ID: CVE-2026-41089 Severity: CVSS 9.8 Target Component: Windows Server Active Directory Netlogon RPC

← Back to the June 4 Security Roundup

Overview

CVE-2026-41089 is a critical stack-based buffer overflow in the Windows Netlogon service (netlogon.dll) that allows an unauthenticated remote attacker to execute arbitrary code with SYSTEM privileges on any reachable domain controller. Active exploitation was confirmed on May 29, 2026, when Belgium's Centre for Cybersecurity (CCB) published a public warning and a proof-of-concept became available. CVSS v3.1 base score: 9.8 (Critical).

Affected Versions

  • Windows Server 2019 (all builds prior to June 2026 Patch Tuesday)
  • Windows Server 2022 (all builds prior to June 2026 Patch Tuesday)
  • Windows Server 2025 (all builds prior to June 2026 Patch Tuesday)
  • Windows Server 2016 (ESU – patch available)

Vulnerability Details

The flaw resides in the Netlogon Remote Protocol (MS-NRPC) message parser. When processing a specially crafted NetrServerAuthenticate3 or NetrLogonSamLogonWithFlags request, the service copies a caller-controlled credential blob into a fixed-size stack buffer without validating the supplied length. An attacker who controls the buffer content can overwrite the saved return address and redirect execution.

Because Netlogon listens on TCP/135 (DCE/RPC endpoint mapper) and dynamically assigned RPC ports, the attack surface is exposed on every domain controller that has not blocked inter-DC and client-to-DC RPC traffic at the network boundary.

Attack Chain

  1. Recon: Attacker enumerates domain controllers via LDAP (_ldap._tcp.dc._msdcs.<domain> DNS SRV records) or direct port scanning on TCP 135+49152-65535.
  2. Trigger: Attacker opens an unauthenticated DCE/RPC bind to the Netlogon interface ({12345678-1234-ABCD-EF00-0123456789AB}) and sends a malformed credential blob (>512 bytes) in NetrServerAuthenticate3.
  3. Stack smash: The overflowed return address is replaced with a ROP gadget in netlogon.dll. Reliable exploitation uses a heap spray to land shellcode in a predictable location.
  4. SYSTEM shell: The ROP chain calls VirtualProtect + executes staged shellcode. Because Netlogon runs as SYSTEM, the attacker immediately obtains a SYSTEM-level reverse shell.
  5. Domain compromise: With SYSTEM on a DC, attacker runs mimikatz lsadump::dcsync to extract the krbtgt hash and forge Golden Tickets for persistent domain-wide access.

Indicators of Compromise (IOCs)

  • Anomalous unauthenticated DCE/RPC binds to the Netlogon interface from external or untrusted subnets
  • Windows Event ID 5820 (Netlogon – "Netlogon could not add the AuthZ RPC interface") in rapid succession
  • Unusual lsass.exe child processes or DLL injection into lsass following Netlogon RPC activity
  • Network traffic: large (>512 byte) NetrServerAuthenticate3 request blobs to TCP 49152-65535 on DCs

Remediation

# 1. Apply the June 2026 Patch Tuesday updates on ALL domain controllers simultaneously.
#    Partial patching leaves remaining DCs exploitable.

# 2. Verify patch is applied
Get-HotFix -Id KB5060842   # Windows Server 2022
Get-HotFix -Id KB5060840   # Windows Server 2019
Get-HotFix -Id KB5060836   # Windows Server 2025

# 3. Short-term: block unauthenticated RPC to DCs at the firewall
#    Allow only trusted client subnets to reach TCP 135 + dynamic RPC ports on DCs
#    Using Windows Firewall (run on each DC):
New-NetFirewallRule -DisplayName "Block Anon Netlogon RPC" `
  -Direction Inbound -Protocol TCP -LocalPort 135 `
  -RemoteAddress "0.0.0.0/0" -Action Block -Profile Domain

# 4. Enable Netlogon secure channel enforcement (if not already done post-Zerologon)
#    Ensure FullSecureChannelProtection = 1 in the registry:
Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters" `
  -Name "FullSecureChannelProtection" -Value 1 -Type DWord

← Back to the June 4 Security Roundup


Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther