GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Dr. Christopher Kunz (christopherkunz@chaos.social)'s status on Tuesday, 02-Jun-2026 11:42:27 JST Dr. Christopher Kunz Dr. Christopher Kunz

    So CVE-2026-41089 (CVSS 9.8) in Windows Netlogon can be triggered by sending a username that is AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA or longer.
    How original.

    In conversation about 2 months ago from chaos.social permalink
    • Embed this notice
      :rainbowCrow: (cr0w@infosec.exchange)'s status on Thursday, 04-Jun-2026 23:54:04 JST :rainbowCrow: :rainbowCrow:
      in reply to
      • Will Dormann

      @christopherkunz @wdormann Here's a new one to take a look at. I haven't gone through it and can't vouch for its legitimacy, but y'all know what you're doing more than I do anyway: https://github.com/Vanquishermacdetach/CVE-2026-41089-509

      In conversation about 2 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: opengraph.githubassets.com
        GitHub - Vanquishermacdetach/CVE-2026-41089-509: CVE-2026-41089 PoC — Netlogon CLDAP stack buffer overflow (CVSS 9.8 CRITICAL)
        CVE-2026-41089 PoC — Netlogon CLDAP stack buffer overflow (CVSS 9.8 CRITICAL) - Vanquishermacdetach/CVE-2026-41089-509
    • Embed this notice
      Dr. Christopher Kunz (christopherkunz@chaos.social)'s status on Thursday, 04-Jun-2026 23:54:07 JST Dr. Christopher Kunz Dr. Christopher Kunz
      in reply to
      • Will Dormann

      @wdormann Of all the writeups, I think I like this one best, especially with it having a human name in the byline: https://adscanpro.com/blog/patch-diffing-cve-2026-41089-netlogon
      "read advisories carefully before deciding how to allocate research time." made me chuckle.

      In conversation about 2 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: adscanpro.com
        Patch Diffing CVE-2026-41089: Locating the Netlogon Bug in 4 Hours Without a Public PoC
        Walkthrough of how to bindiff a Patch Tuesday Windows CVE end-to-end — from MSU acquisition to function-level bug identification. CVE-2026-41089 (Netlogon pre-auth RCE) as the running example. Methodology, tooling, and the honest limits of trigger development without weeks of exploit engineering.
    • Embed this notice
      Will Dormann (wdormann@infosec.exchange)'s status on Thursday, 04-Jun-2026 23:54:08 JST Will Dormann Will Dormann
      in reply to

      @christopherkunz
      Yes, my test environments (unpatched Server 2016, 2022, and 2025) all had a maximum DNS suffix of 64 chars. (Longer isn't allowed)

      In conversation about 2 months ago permalink

      Attachments


      1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/692/049/575/250/713/original/3ef786e32d2e758c.png

      2. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/692/058/641/106/787/original/9d54baff81429e7d.png

      3. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/692/066/460/411/287/original/66e42781919dfaa6.png
    • Embed this notice
      Will Dormann (wdormann@infosec.exchange)'s status on Thursday, 04-Jun-2026 23:54:08 JST Will Dormann Will Dormann
      in reply to

      @christopherkunz
      I also tested another PoC and it was even more fake. i.e. it didn't even create a CLDAP structure that made sense.

      I get that PoC||GTFO is a thing, but we've clearly entered a phase where it needs to be Verified PoC||GTFO. 🤦♂️

      In conversation about 2 months ago permalink

      Attachments


      1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/692/083/358/777/859/original/77e9c8cd6e0af56f.png
    • Embed this notice
      Will Dormann (wdormann@infosec.exchange)'s status on Thursday, 04-Jun-2026 23:54:10 JST Will Dormann Will Dormann
      in reply to

      @christopherkunz
      😂

      I miss the days when things like this were written by humans, using logic and facts. As opposed to statistically plausible slop.

      In conversation about 2 months ago permalink
    • Embed this notice
      Dr. Christopher Kunz (christopherkunz@chaos.social)'s status on Thursday, 04-Jun-2026 23:54:10 JST Dr. Christopher Kunz Dr. Christopher Kunz
      in reply to
      • Will Dormann

      @wdormann From what I read in the writeup (and the sparse other sources), you need a long enough DNS name on the victim host to trigger the overflow. I think 54 chars or more? This github has a possible explanation why the PoC fails under most normal conditions: https://github.com/ADScanPro/CVE-2026-41089-LongLogon

      In conversation about 2 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: opengraph.githubassets.com
        GitHub - ADScanPro/CVE-2026-41089-LongLogon: CVE-2026-41089 checker: unauthenticated, non-destructive detection for the Netlogon CLDAP stack buffer overflow (CVSS 9.8). Reports whether a domain controller's domain is long enough to crash, without sending the overflow. The binary-verified analysis the public PoCs got wrong.
        CVE-2026-41089 checker: unauthenticated, non-destructive detection for the Netlogon CLDAP stack buffer overflow (CVSS 9.8). Reports whether a domain controller's domain is long enough to crash,...
    • Embed this notice
      Dr. Christopher Kunz (christopherkunz@chaos.social)'s status on Thursday, 04-Jun-2026 23:54:11 JST Dr. Christopher Kunz Dr. Christopher Kunz
      in reply to
      • Will Dormann

      @wdormann This writeup *seems* to make sense, were it not for the magic two letters in the TLD: https://aretiq.ai/research/vul260513-cve-2026-41089-microsoft-windows-netlogon-buildsamlogonresponse-stack-based-buffer-overflow-rce/

      In conversation about 2 months ago permalink

      Attachments

      1. No result found on File_thumbnail lookup.
        CVE-2026-41089 — Microsoft Windows Netlogon BuildSamLogonResponse Stack-based Buffer Overflow RCE
        from Aretiq AI
        1. Overview A stack-based buffer overflow vulnerability exists in the Windows Netlogon service’s DC locator ping response handler. When a domain controller processes a CLDAP search request, it serializes response data including attacker-supplied and server-side strings into a fixed-size stack buffer without adequate bounds checking. An unauthenticated remote attacker can send a single crafted CLDAP packet to a domain controller’s UDP port 389, causing the Netlogon service to crash the LSASS process and force the domain controller to reboot. The exploitability depends on the target domain controller’s DNS naming configuration — domain controllers with longer DNS domain names and hostnames are vulnerable. Microsoft addressed this vulnerability in the May 2026 security update.
    • Embed this notice
      Will Dormann (wdormann@infosec.exchange)'s status on Thursday, 04-Jun-2026 23:54:12 JST Will Dormann Will Dormann
      in reply to

      @christopherkunz
      Yeah, I've seen what it claims to do.
      But either they are hand-waving over a critical requirement of what it takes to repro, or it's fake.

      In conversation about 2 months ago permalink
    • Embed this notice
      Will Dormann (wdormann@infosec.exchange)'s status on Thursday, 04-Jun-2026 23:54:13 JST Will Dormann Will Dormann
      in reply to

      @christopherkunz
      Ah, so you've confirmed that it works?
      With AI and clout seeking these days, we've long passed the "PoC exists on Github" thing having any meaning whatsoever. 😂

      Personally, I couldn't get that one to do anything.

      In conversation about 2 months ago permalink
    • Embed this notice
      Dr. Christopher Kunz (christopherkunz@chaos.social)'s status on Thursday, 04-Jun-2026 23:54:13 JST Dr. Christopher Kunz Dr. Christopher Kunz
      in reply to
      • Will Dormann

      @wdormann https://chaos.social/@christopherkunz/116676523296824499

      In conversation about 2 months ago permalink

      Attachments

      1. No result found on File_thumbnail lookup.
        Dr. Christopher Kunz (@christopherkunz@chaos.social)
        from Dr. Christopher Kunz
        @FritzAdalis@infosec.exchange @cR0w@infosec.exchange It's a little more complicated (and I have no means to verify the purported PoC, but it looks legit-ish), but apparently you can crash LSASS by sending a CLDAP DC locator ping packet with the username being Ax130 or longer. Code execution seems possible (according to MSRC), but the PoC is just a DoS.
    • Embed this notice
      Will Dormann (wdormann@infosec.exchange)'s status on Thursday, 04-Jun-2026 23:54:14 JST Will Dormann Will Dormann
      in reply to

      @christopherkunz
      Reference?

      In conversation about 2 months ago permalink
    • Embed this notice
      Dr. Christopher Kunz (christopherkunz@chaos.social)'s status on Thursday, 04-Jun-2026 23:54:14 JST Dr. Christopher Kunz Dr. Christopher Kunz
      in reply to
      • Will Dormann

      @wdormann https://github.com/0xABCD01/CVE-2026-41089/blob/main/poc.py#L234

      In conversation about 2 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: opengraph.githubassets.com
        CVE-2026-41089/poc.py at main · 0xABCD01/CVE-2026-41089
        CVE-2026-41089 PoC — Netlogon CLDAP stack buffer overflow (CVSS 9.8 CRITICAL) - 0xABCD01/CVE-2026-41089

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.