Impact
The vulnerability is a stack-based buffer overflow in the Windows Netlogon service that lets an attacker send specially crafted packets to the Netlogon protocol and trigger a buffer overrun. This allows execution of arbitrary code with the service’s system-level privileges, giving the attacker full control of the affected host. The weakness is identified as CWE-121.
Affected Systems
The flaw affects Microsoft Windows 10 from versions 1607, 1809, 21H2, and 22H2; Windows 11 from 23H2 through 26H1; and Microsoft Windows Server from 2012 up to 2025, including all Server Core installations. Any machine running Netlogon that is reachable over a network is potentially vulnerable.
Risk and Exploitability
The CVSS score of 9.8 marks this as a critical vulnerability; no EPSS data is available and it is not listed in the CISA KEV catalog. The attack vector is remote, accessed over the network via the Netlogon/NTLM authentication traffic. An attacker who can reach the target’s Netlogon service can exploit the buffer overflow without local privileges or user interaction.
OpenCVE Enrichment