Executive brief
Windows Netlogon is the core authentication service that verifies user identities across Windows domain networks. An attacker on an adjacent network can spoof authentication messages to bypass security checks and gain unauthorized access to domain-joined systems without valid credentials.
Technical details
This vulnerability is an authentication bypass in Windows Netlogon that exploits insufficient validation of spoofed authentication messages. The attack is conducted over an adjacent network (requiring network proximity but not direct network access), allowing an unauthenticated attacker to forge Netlogon requests and impersonate legitimate users or systems. The vulnerability enables attackers to bypass Netlogon's integrity checks and authenticate to domain resources without possessing valid credentials. A patch is available from Microsoft through the Security Update Guide.
Affected products
- Microsoft Windows Netlogon
Timeline
- 2026-09-08: disclosed