Junglewise Threat Intelligence

CVE-2026-41089: Microsoft Windows stack-based buffer overflow in Netlogon

CVE-2026-41089 · Severity: critical · CVSS 9.8 · Published 2026-05-12

Executive brief

A critical vulnerability has been identified in the Windows Netlogon service, which manages user authentication and domain connectivity. An unauthorized attacker can exploit this flaw over the network to take full control of an affected system without any user interaction. This could lead to a complete compromise of corporate domain controllers, resulting in data theft, service outages, and a total loss of network integrity.

Technical details

This vulnerability is a stack-based buffer overflow (CWE-121) residing within the Windows Netlogon service. The flaw is triggered when the service improperly handles specially crafted authentication requests sent over the network. Because the attack vector is network-based and requires no prior authentication or user interaction (AV:N/AC:L/PR:N/UI:N), it is highly wormable. Successful exploitation allows for remote code execution (RCE) in the context of the SYSTEM account, typically on Domain Controllers or domain-joined servers. Microsoft has released security updates to address this issue in the May 2026 patch cycle.

Affected products

  • Microsoft Windows All supported versions including Windows Server

Timeline

  • 2026-05-12: disclosed: Vulnerability disclosed by Microsoft and assigned CVE-2026-41089.
  • 2026-05-12: advisory: Microsoft Security Update Guide published.

References

Related threats