0xABCD01
CVE-2026-41089
Netlogon and CLDAP vulnerability research with a proof of concept.
Documentation snapshot
README 快照
翻译暂时拿不到。
机器翻译的项目简介,仅供参考。原文在下方,也可以直接用浏览器自带的整页翻译 (Chrome / Edge 点地址栏右侧的翻译图标,或用右键菜单里的「翻译成中文」)。
下面正文是项目自己的英文 README。想读全文就用浏览器自带的整页翻译: Chrome / Edge 点地址栏右侧的翻译图标,或用右键菜单里的「翻译成中文」; 手机浏览器一般在菜单里。
本页保存的是公开项目资料快照,阅读过程不需要连接 GitHub。
CVE-2026-41089
██████╗██╗ ██╗███████╗ ██╗ ██╗ ██╗ ██████╗ ██████╗
██╔════╝██║ ██║██╔════╝ ██║ ██║███║██╔═████╗██╔═████╗
██║ ██║ ██║█████╗ ███████║╚██║██║██╔██║██║██╔██║
██║ ╚██╗ ██╔╝██╔══╝ ██╔══██║ ██║████╔╝██║████╔╝██║
╚██████╗ ╚████╔╝ ███████╗ ██║ ██║ ██║╚██████╔╝╚██████╔╝
╚═════╝ ╚═══╝ ╚══════╝ ╚═╝ ╚═╝ ╚═╝ ╚═════╝ ╚═════╝
Windows Netlogon Remote Code Execution via CLDAP Stack Buffer Overflow
图片:CVSS 图片:CWE 图片:Python 图片:License
One crafted UDP packet to port 389 overflows a 528-byte stack buffer inside LSASS on any unpatched Windows Domain Controller. The process crashes. The DC reboots in ~60 seconds. No authentication required.
| Attack Vector | UDP 389 (CLDAP), pre-auth, zero credentials |
| Impact | LSASS crash, DC reboot, potential RCE |
| CWE | CWE-121 (Stack-based Buffer Overflow) |
| CVSS Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Published | May 12, 2026 by Microsoft |
Quick Start
python3 poc.py 10.0.50.21 corp.local
Three phases: normal ping to confirm the DC is alive, overflow ping with a 130-character username, liveness check. Takes ~10 seconds.
Affected Systems
Every Windows Server version running as a Domain Controller:
| Server Version | Fixed In |
|---|---|
| 2012 / 2012 R2 | ESU-only patches |
| 2016 | 10.0.14393.9140 |
| 2019 | 10.0.17763.8755 |
| 2022 | 10.0.20348.5074 |
| 2022 23H2 | 10.0.25398.2330 |
| 2025 | 10.0.26100.32772 |
Root Cause
NlGetLocalPingResponse allocates a 528-byte stack buffer and hands it
to BuildSamLogonResponse. That function calls NetpLogonPutUnicodeString
to write server name, domain name, GUIDs, and the attacker-controlled
username into the buffer.
The bug: NetpLogonPutUnicodeString receives a maximum length in bytes
but treats it as a WCHAR count. Every string written through this path
occupies twice the expected space. The “User” field in the CLDAP filter
(up to 130 wchars, 260 bytes on the wire) pushes the combined write
past the 528-byte boundary.
I_NetLogonLdapLookupEx
-> NlGetLocalPingResponse // 528-byte stack buffer
-> LogonRequestHandler
-> BuildSamLogonResponse
-> NetpLogonPutUnicodeString // byte/WCHAR size confusion
Usage
python3 poc.py [options]
| Flag | Description | Default |
|---|---|---|
-l | Username length in characters | 130 |
-t | UDP recv timeout (seconds) | 5 |
-d | Delay between overflow and liveness check (seconds) | 3 |
# Connectivity test (short username, no overflow)
python3 poc.py 10.0.50.21 corp.local
# Default overflow attempt
python3 poc.py 10.0.50.21 corp.local -l 130
# Larger payload, longer timeout for slow networks
python3 poc.py 10.0.50.21 corp.local -l 200 -t 10
Requires Python 3.8+. No third-party packages.
How It Works
- Phase 1. A normal CLDAP ping with username “testuser” confirms the target responds on UDP 389.
- Phase 2. The same packet structure, but the username is 130+ characters of “A”. This pushes the serialized data past the stack buffer boundary. If LSASS crashes, the recv times out.
- Phase 3. After a configurable delay, a second normal ping checks whether the DC is still alive. No response = LSASS crash confirmed.
The overflow triggers a denial of service (LSASS crash, DC reboot). RCE through stack corruption is possible in theory. This PoC does not attempt code execution.
Detection
Network. Scan CLDAP traffic for search requests where the “User” filter attribute exceeds 20-30 characters. Normal DC locator pings use service account names (short strings).
Host. Watch for LSASS crashes tied to netlogon.dll (Event ID 1000). Enable Netlogon debug logging:
nltest /dbflag:0x2080ffff
Mitigation
- Install the May 2026 Microsoft security update
- Restrict UDP 389 inbound to trusted management subnets
- For legacy Server versions out of ESU: 0patch ships micropatches
(single instruction fix:
mov edx, 0x40to halve the max username length)
References
- Microsoft Security Update Guide
- NVD - CVE-2026-41089
- 0patch Analysis and Micropatch
- Aretiq AI Reverse Engineering
- RFC 4511 - LDAP
- MS-ADTS - CLDAP DC Locator
Legal. This code exists for authorized security research and education. Test only against systems you own or have written permission to test. Unauthorized access to computer systems violates the CFAA and equivalent laws in most jurisdictions.
MIT License
Official distribution
获取与安装
暂未发现可确认的官方软件包地址
当前 README 快照没有出现 npm、PyPI、Crates.io、pub.dev 等官方包页链接。本站不会根据仓库名称猜测下载地址。
本站不托管项目文件;需要安装时,请以项目维护者发布的官方文档为准。
Before installing
使用前核验
本站保存公开资料用于阅读,不代表安全审计或功能背书。安装前请核对许可证、依赖来源和发布签名,不要直接运行来源不明的二进制文件或高权限脚本。