Make money doing the work you believe in

Microsoft patched CVE-2026-41089 in the May 12 Patch Tuesday release as one of 118 vulnerabilities addressed that month. The flaw is a stack-based buffer overflow in the Windows Netlogon RPC interface that allows an unauthenticated remote attacker to send a specially crafted network request to a Windows server acting as a domain controller and execute code with SYSTEM-level privileges.

Microsoft assigned a CVSS score of 9.8. No user interaction is required and no prior authentication is needed. On June 1, Belgium’s Centre for Cybersecurity confirmed active exploitation.

Domain controllers are the master keys to Active Directory own the DC, own every user account, every group policy, every authentication event across the entire enterprise. An unauthenticated, remote, SYSTEM-level exploit against domain controllers is about as catastrophic as enterprise vulnerabilities get.

This is a CVSS 9.8 that is actively being exploited in the wild right now. If you have not patched your Windows DCs from the May 12 Patch Tuesday, stop reading this post and do it immediately.

Jul 14
at
10:32 AM
Relevant people

Log in or sign up

Join the most interesting and insightful discussions.