← 목록으로 돌아가기

보안 뉴스 · 취약점

2026-007: Critical Vulnerability in Windows Netlogon

출처
CERT-EU
원문 게시일
마지막 본문 수집
2026. 09. 14. 16:40 KST

출처: CERT-EU · © Cybersecurity Service for the Union institutions, bodies, offices and agencies (CERT-EU). · CC BY 4.0
문서 서식과 링크를 FineTS 화면에 맞게 정리했습니다. 이미지·첨부파일은 공식 원문에서 확인하세요.

공식 원문에서 읽기 ↗
기사 원문에 등장한 CVE별 취약점, 설명, 조치사항
취약점설명조치사항
CVE-2026-41089

Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.

조치사항 확인이 필요합니다.

한국어 버튼을 눌러 번역을 요청할 수 있습니다.

On 12 May 2026, Microsoft published a security advisory addressing a critical vulnerability affecting Windows Server when acting as a domain controller. This vulnerability allows an unauthenticated attacker to execute arbitrary code over a network. According to The Centre for Cybersecurity Belgium (

History:

  • 10/06/2026 --- v1.0 -- Initial publication

Summary

On 12 May 2026, Microsoft published a security advisory addressing a critical vulnerability affecting Windows Server when acting as a domain controller [1]. This vulnerability allows an unauthenticated attacker to execute arbitrary code over a network.

According to The Centre for Cybersecurity Belgium (CCB), this vulnerability is currently exploited by threat actors [2]. It is strongly recommended updating affected Windows servers as soon as possible.

Technical Details

The vulnerability CVE-2026-41089, with the CVSS score of 9.8, is a stack-based buffer overflow in Windows Netlogon [1].

An unauthenticated attacker could execute arbitrary code with SYSTEM privileges on targeted domain controllers by sending specially crafted packets [3].

Affected Products

The following Windows Server versions are affected:

  • Windows Server 2012 / 2012 R2
  • Windows Server 2016 (prior to 10.0.14393.9140)
  • Windows Server 2019 (prior to 10.0.17763.8755)
  • Windows Server 2022 (prior to 10.0.20348.5074)
  • Windows Server 2022 23H2 (prior to 10.0.25398.2330)
  • Windows Server 2025 (prior to 10.0.26100.32772)

Additional information is available in the vendor’s advisory [1].

Recommendations

It is recommended updating affected Windows Server asset as soon as possible.

References

[1] https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41089

[2] https://ccb.belgium.be/advisories/warning-microsoft-patch-tuesday-may-2026-patches-118-vulnerabilities-16-critical-102#:~:text=It%20is%20now%20actively%20exploited%20in%20the%20wild

[3] https://www.bleepingcomputer.com/news/microsoft/critical-windows-netlogon-remote-code-execution-flaw-now-exploited-in-attacks/

공식 원문에서 읽기 ↗

← 목록으로 돌아가기