Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-41089-PoC — CVE-2026-41089 LongLogon: pre-auth CLDAP (UDP/389) stack buffer overflow crasher for unpatched Windows Server 2025 Netlogon (lsass 0xc0000409). Stdlib-only Python PoC + lab write-up. | Kitploit
Tools/GitHubGitHub/1posix/cve-2026-41089-poc
Vulnerability AnalysisExploitationNetwork SecurityPenetration TestingRed Teaming
GitHub1posix/cve-2026-41089-poc

CVE-2026-41089-PoC

CVE-2026-41089 LongLogon: pre-auth CLDAP (UDP/389) stack buffer overflow crasher for unpatched Windows Server 2025 Netlogon (lsass 0xc0000409). Stdlib-only Python PoC + lab write-up.

View Repository
5 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-41089 — LongLogon (crasher PoC)

Pre-authentication stack buffer overflow in the Netlogon service of Windows Server 2025. A single CLDAP packet (UDP/389) from any host on the wire is enough: lsass.exe dies with STATUS_STACK_BUFFER_OVERRUN (0xc0000409) and the domain controller reboots.

  • Component: netlogon.dll, NlGetLocalPingResponse / BuildSamLogonResponse
  • Vector: one UDP/389 packet, unauthenticated
  • Impact: DoS (lsass.exe crash, DC reboot)
  • Patched in: build 10.0.26100.32772 and later

How it works

The response to a Netlogon CLDAP ping is serialized into a 528-byte stack buffer. The server writes its own names (forest, domain, hostname) followed by the attacker-controlled User field (capped at 130 wide chars). When the total fill reaches 536 bytes (buffer + stack cookie), the trailing L'\0' overwrites the /GS cookie and the process crashes.

The NtVer field routes the code path: 0x02 takes the vulnerable BuildSamLogonResponse, while 0x06 / 0x16 take the bounded (safe) BuildSamLogonResponseEx. This PoC sends NtVer = 0x02.

Requirements

  • Unpatched Windows Server 2025 DC: netlogon.dll < 10.0.26100.32772
  • A long DNS domain so the projected fill (User=130) reaches >= 536 bytes. Windows Server 2025 caps AD domain names at 64 characters; with a 63-char hostname the measured fill is 581 bytes (guaranteed crash). Shorter combinations (e.g. 533 bytes) are borderline.
  • UDP/389 reachable from the attacking host
  • Python >= 3.9 (stdlib only, no dependencies)

Usage

python3 longlogon_exploit.py <dc-ip> <dc-dns-domain> [--dry-run] [--shots N] [--confirm-wait S] [--force]

--dry-run probe with User=1 (benign), show projected fill, do not fire --shots N number of overflow packets to send (default 1) --confirm-wait S wait before re-probing after a silent shot (default 75s) --force fire even if the projected fill is under 536 bytes

Example (replace the IP and the domain with your lab values):

python3 longlogon_exploit.py 192.168.1.10 cve202641089.xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx.example --dry-run
python3 longlogon_exploit.py 192.168.1.10 cve202641089.xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx.example

Expected output of the fire:

[*] CVE-2026-41089 LongLogon crasher -> 192.168.1.10 (domain 64 chars)
[*] DC alive. Probe fill (User=1) = 323 B; projected fill (User=130) = 581 B (buffer 528, cookie 536)
[*] Firing overflow: NtVer=0x02, User=130 chars, shots=1
    shot #1: NO REPLY (5.01 s) -> possible crash (or lost packet)
[*] Waiting 75 s to let the DC (re)start, then re-probing...
[+] DC STILL DOWN after overflow + re-probe -> CRASH LIKELY (reboot in progress or dump pending)

Exit codes: 0 crash likely, 1 DC silent on the initial probe, 2 fill under 536 bytes (borderline), 3 DC survived.

Note: the script re-probes after 75 seconds because a single silent packet can also be a lost UDP datagram. Do not conclude a crash from silence alone.

Precondition check (non-destructive)

Use the official checker from the research repo. It probes with User=1, so the DC stays up:

git clone https://github.com/ADScanPro/CVE-2026-41089-LongLogon && cd CVE-2026-41089-LongLogon
python3 run longlogon.py <dc-ip> <dc-dns-domain>

Expected: "PRECONDITION MET" with a projected fill of at least 536 bytes.

The checker does not prove the patch state: a patched DC takes the same code path and simply refuses the over-long write. Check the netlogon.dll version on the DC directly (< 10.0.26100.32772 = vulnerable).

Confirmation after the crash

On the DC, once it is back up:

(Get-CimInstance Win32_OperatingSystem).LastBootUpTime
Get-WinEvent -FilterHashtable @{LogName='Application'; Id=1000} -MaxEvents 5

Look for event 1000: faulting application lsass.exe, faulting module netlogon.DLL, exception code 0xc0000409, and a boot time later than the shot.

Lab results

Tested on Windows Server 2025, lsass.exe 10.0.26100.7309, netlogon.dll 10.0.26100.32230 (unpatched), 64-char domain + 63-char hostname (projected fill 581 bytes). One packet fired:

    Application Error (Id 1000):
      Faulting application: lsass.exe, version: 10.0.26100.7309
      Faulting module:    netlogon.DLL, version: 10.0.26100.32230
      Exception code:     0xc0000409        (STATUS_STACK_BUFFER_OVERRUN)
      Fault offset:       0x000000000002399d

    LastBootUpTime: 17:19:42   (crash logged at 17:18:37)

Notes

  • DoS, not RCE, by default: the /GS cookie turns the overflow into a controlled crash before the return address is reached. The User field is fully attacker-controlled, which is a theoretical path to code execution.
  • Borderline window: between 528 and 535 bytes of fill the crash is not guaranteed (lab measurements: 535 B = 6/6 crashes, 534 B = 0/6).
  • The crash is non-idempotent: take a snapshot of the DC before firing.
  • After a crash the DC may come back with Netlogon DBFlag 0x2080FFFF (repair mode), which is normal after an lsass crash.

Disclaimer

This PoC is provided for educational and research purposes only. It was developed and tested in an isolated lab environment on Windows Server 2025. Use it at your own risk.

By using this script you agree that the author is not liable for any loss of data, service interruption, hardware damage, or other direct or indirect consequences. The crash is non-idempotent: the target domain controller will reboot. Take a snapshot before firing.

No warranty is made that this PoC works in a production environment or on all builds of Windows Server 2025.

References

  • Research and checker: https://github.com/ADScanPro/CVE-2026-41089-LongLogon
  • Write-up: https://adscanpro.com/blog/patch-diffing-cve-2026-41089-netlogon
Download Tool