Junglewise Threat Intelligence

CVE-2026-72982: Microsoft Windows Netlogon stack-based buffer overflow

CVE-2026-72982 · Severity: critical · CVSS 9.8 · Published 2026-09-08

Executive brief

Windows Netlogon is a core authentication service used by organizations to manage user accounts and credentials across domain networks. A stack-based buffer overflow vulnerability in this component allows attackers on the network to execute arbitrary code without authentication, potentially compromising entire Windows domains and granting them control over critical systems.

Technical details

A stack-based buffer overflow exists in the Windows Netlogon service that can be exploited remotely over the network without prior authentication. The vulnerability stems from insufficient bounds checking in the handling of network messages, allowing an attacker to overwrite stack memory and execute arbitrary code with the privileges of the Netlogon service. The attack vector is network-based and requires only the ability to reach the Netlogon service port; no user interaction or valid credentials are needed. An attacker can leverage this to gain code execution on domain controllers and member systems, potentially leading to complete domain compromise.

Affected products

  • Microsoft Windows

Timeline

  • 2026-09-08: disclosed

References

Related threats