ZeroHour

CVE-2026-62759

mass

Authentication Bypass by Spoofing in Windows Netlogon Service

CVSS 3.1
7.5 high
EPSS
<1%p18
Published
()
Modified
AI analysis

CVE-2026-62759 is an authentication bypass by spoofing flaw (CWE-290) in the Windows Netlogon service, the component that handles domain authentication and secure channel establishment. An unauthenticated attacker positioned on an adjacent network — the same LAN, Wi-Fi segment, or VPN segment — can impersonate a legitimate party during Netlogon authentication exchanges; the high attack complexity (AC:H) indicates specific conditions must be met for the spoofing to succeed. A successful spoof defeats authentication checks, yielding high impact across confidentiality, integrity, and availability, such as impersonating a trusted endpoint (for example a domain controller or domain-joined client) in authentication traffic. Any organization running Windows domains is potentially affected, since Netlogon runs on domain controllers and on essentially all Windows client and server machines. There is currently no known exploitation: the flaw is not in CISA's KEV, EPSS gives it only a 0.3% probability of exploitation in the next 30 days (18th percentile), and no public proof-of-concept is known.

What to do: Prioritize applying Microsoft's security update for this CVE as soon as the patched builds are identified in Microsoft's advisory, starting with domain controllers. In the interim, restrict adjacent-network access to domain controllers and other sensitive hosts (network segmentation, lockdown of guest Wi-Fi and flat VPN segments) and monitor Netlogon/secure-channel traffic for anomalous authentication attempts.

Affected
Microsoft Windows Netlogon service (Windows client and Windows server editions)
Estimated exposure
masshundreds of millions of Windows endpoints and millions of domain controllers (Netlogon ships with effectively every Windows installation) — Netlogon is a core Windows component present on virtually all Windows client and server machines, and is critically exposed on domain controllers wherever attackers can reach an adjacent network segment.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Authentication bypass by spoofing in Windows Netlogon allows an unauthorized attacker to perform spoofing over an adjacent network.

Weakness
CWE-290
Vector
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.