CVE-2026-72982
massUnauthenticated Stack Buffer Overflow RCE in Windows Netlogon
CVE-2026-72982 is a stack-based buffer overflow (CWE-121) in the Windows Netlogon service, assigned by Microsoft with a critical CVSS 3.1 score of 9.8. A remote, unauthenticated attacker can trigger the flaw by sending crafted network traffic to the Netlogon service, with no privileges or user interaction required (AV:N/AC:L/PR:N/UI:N). Successful exploitation yields full code execution with high impact on confidentiality, integrity, and availability, meaning an attacker could take over the service host system. Any Windows deployment running Netlogon is potentially affected, with domain controllers and other systems exposing the service over the network facing the greatest risk. There is currently no known exploitation, no public proof-of-concept, and the flaw is not in CISA's KEV, with EPSS estimating a 0.9% chance of exploitation within 30 days.
What to do: Monitor the Microsoft release ([email protected] is the CNA) and apply the Windows security update it provides as soon as it is available via Windows Update, prioritizing domain controllers and any systems with Netlogon reachable from untrusted networks. Until patching, restrict unauthenticated network access to Netlogon/RPC endpoints with firewalls or segmentation, and check which Windows versions Microsoft marks affected once the advisory details are published. Watch for addition to CISA KEV and rises in EPSS as indicators of increased exploitation risk.
| Microsoft Windows Netlogon service | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.
- Weakness
- CWE-121
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.