CVE-2026-72982

9.8

Microsoft · Windows

A stack-based buffer overflow in the Windows Netlogon service allows an unauthenticated remote attacker to execute arbitrary code.

Executive summary

A critical stack-based buffer overflow in the Windows Netlogon service exposes multiple Windows 10 and 11 versions to unauthenticated remote code execution.

Vulnerability

This is a stack-based buffer overflow (CWE-121) within the Netlogon component. The vulnerability is exploitable by an unauthenticated attacker over the network, requiring no user interaction.

Business impact

This vulnerability carries a CVSS score of 9.8, reflecting its critical severity. Successful exploitation allows an attacker to gain full control over the affected system, leading to potential data exfiltration, unauthorized administrative access, and complete system compromise. Given the ubiquity of the Netlogon service in enterprise environments, this flaw poses a significant risk to organizational integrity and operational continuity.

Remediation

Immediate Action: Apply the vendor-provided security updates immediately to reach the fixed build versions, such as 10.0.14393.9512 for Windows 10 Version 1607, as documented in the Microsoft Security Update Guide.

Proactive Monitoring: Review security event logs for anomalous traffic patterns directed at the Netlogon service or unexpected service crashes that may indicate exploitation attempts.

Compensating Controls: Restrict network access to the Netlogon service via host-based firewalls or network segmentation to limit exposure to trusted internal segments where feasible.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Due to the critical nature of this vulnerability and the potential for full system compromise, immediate patching is required. IT administrators should prioritize the deployment of the provided fixes across all affected Windows 10 and 11 endpoints to eliminate the risk of remote code execution.

More Microsoft CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources