CVE-2026-62759
massAuthentication Bypass by Spoofing in Windows Netlogon Service
CVE-2026-62759 is an authentication bypass by spoofing flaw (CWE-290) in the Windows Netlogon service, the component that handles domain authentication and secure channel establishment. An unauthenticated attacker positioned on an adjacent network — the same LAN, Wi-Fi segment, or VPN segment — can impersonate a legitimate party during Netlogon authentication exchanges; the high attack complexity (AC:H) indicates specific conditions must be met for the spoofing to succeed. A successful spoof defeats authentication checks, yielding high impact across confidentiality, integrity, and availability, such as impersonating a trusted endpoint (for example a domain controller or domain-joined client) in authentication traffic. Any organization running Windows domains is potentially affected, since Netlogon runs on domain controllers and on essentially all Windows client and server machines. There is currently no known exploitation: the flaw is not in CISA's KEV, EPSS gives it only a 0.3% probability of exploitation in the next 30 days (18th percentile), and no public proof-of-concept is known.
What to do: Prioritize applying Microsoft's security update for this CVE as soon as the patched builds are identified in Microsoft's advisory, starting with domain controllers. In the interim, restrict adjacent-network access to domain controllers and other sensitive hosts (network segmentation, lockdown of guest Wi-Fi and flat VPN segments) and monitor Netlogon/secure-channel traffic for anomalous authentication attempts.
| Microsoft Windows Netlogon service (Windows client and Windows server editions) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Authentication bypass by spoofing in Windows Netlogon allows an unauthorized attacker to perform spoofing over an adjacent network.
- Weakness
- CWE-290
- Vector
- CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.