ZeroHour

CVE-2026-72982

mass

Unauthenticated Stack Buffer Overflow RCE in Windows Netlogon

CVSS 3.1
9.8 critical
EPSS
<1%p58
Published
()
Modified
AI analysis

CVE-2026-72982 is a stack-based buffer overflow (CWE-121) in the Windows Netlogon service, assigned by Microsoft with a critical CVSS 3.1 score of 9.8. A remote, unauthenticated attacker can trigger the flaw by sending crafted network traffic to the Netlogon service, with no privileges or user interaction required (AV:N/AC:L/PR:N/UI:N). Successful exploitation yields full code execution with high impact on confidentiality, integrity, and availability, meaning an attacker could take over the service host system. Any Windows deployment running Netlogon is potentially affected, with domain controllers and other systems exposing the service over the network facing the greatest risk. There is currently no known exploitation, no public proof-of-concept, and the flaw is not in CISA's KEV, with EPSS estimating a 0.9% chance of exploitation within 30 days.

What to do: Monitor the Microsoft release ([email protected] is the CNA) and apply the Windows security update it provides as soon as it is available via Windows Update, prioritizing domain controllers and any systems with Netlogon reachable from untrusted networks. Until patching, restrict unauthenticated network access to Netlogon/RPC endpoints with firewalls or segmentation, and check which Windows versions Microsoft marks affected once the advisory details are published. Watch for addition to CISA KEV and rises in EPSS as indicators of increased exploitation risk.

Affected
Microsoft Windows Netlogon service
Estimated exposure
masson the order of 1M+ systems (Netlogon ships with all Windows installs; exposed domain controllers and Windows servers number in the hundreds of thousands to… — Netlogon is a core Windows component present on virtually every Windows installation, and public scan data and deployment patterns indicate millions of Windows hosts with unauthenticated Netlogon reachability concentrated on domain…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.

Weakness
CWE-121
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.