So CVE-2026-41089 (CVSS 9.8) in Windows Netlogon can be triggered by sending a username that is AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA or longer.
How original.
Conversation
Notices
-
Embed this notice
Dr. Christopher Kunz (christopherkunz@chaos.social)'s status on Tuesday, 02-Jun-2026 11:42:27 JST
Dr. Christopher Kunz
-
Embed this notice
:rainbowCrow: (cr0w@infosec.exchange)'s status on Thursday, 04-Jun-2026 23:54:04 JST
:rainbowCrow:
@christopherkunz @wdormann Here's a new one to take a look at. I haven't gone through it and can't vouch for its legitimacy, but y'all know what you're doing more than I do anyway: https://github.com/Vanquishermacdetach/CVE-2026-41089-509
-
Embed this notice
Dr. Christopher Kunz (christopherkunz@chaos.social)'s status on Thursday, 04-Jun-2026 23:54:07 JST
Dr. Christopher Kunz
@wdormann Of all the writeups, I think I like this one best, especially with it having a human name in the byline: https://adscanpro.com/blog/patch-diffing-cve-2026-41089-netlogon
"read advisories carefully before deciding how to allocate research time." made me chuckle.In conversation permalink Attachments
-
Embed this notice
Will Dormann (wdormann@infosec.exchange)'s status on Thursday, 04-Jun-2026 23:54:08 JST
Will Dormann
@christopherkunz
Yes, my test environments (unpatched Server 2016, 2022, and 2025) all had a maximum DNS suffix of 64 chars. (Longer isn't allowed)In conversation permalink Attachments
-
Embed this notice
Will Dormann (wdormann@infosec.exchange)'s status on Thursday, 04-Jun-2026 23:54:08 JST
Will Dormann
@christopherkunz
I also tested another PoC and it was even more fake. i.e. it didn't even create a CLDAP structure that made sense.I get that PoC||GTFO is a thing, but we've clearly entered a phase where it needs to be Verified PoC||GTFO. 🤦♂️
In conversation permalink Attachments
-
Embed this notice
Will Dormann (wdormann@infosec.exchange)'s status on Thursday, 04-Jun-2026 23:54:10 JST
Will Dormann
I miss the days when things like this were written by humans, using logic and facts. As opposed to statistically plausible slop.
In conversation permalink -
Embed this notice
Dr. Christopher Kunz (christopherkunz@chaos.social)'s status on Thursday, 04-Jun-2026 23:54:10 JST
Dr. Christopher Kunz
@wdormann From what I read in the writeup (and the sparse other sources), you need a long enough DNS name on the victim host to trigger the overflow. I think 54 chars or more? This github has a possible explanation why the PoC fails under most normal conditions: https://github.com/ADScanPro/CVE-2026-41089-LongLogon
In conversation permalink Attachments
-
Embed this notice
Dr. Christopher Kunz (christopherkunz@chaos.social)'s status on Thursday, 04-Jun-2026 23:54:11 JST
Dr. Christopher Kunz
@wdormann This writeup *seems* to make sense, were it not for the magic two letters in the TLD: https://aretiq.ai/research/vul260513-cve-2026-41089-microsoft-windows-netlogon-buildsamlogonresponse-stack-based-buffer-overflow-rce/
In conversation permalink Attachments
-
Embed this notice
Will Dormann (wdormann@infosec.exchange)'s status on Thursday, 04-Jun-2026 23:54:12 JST
Will Dormann
@christopherkunz
Yeah, I've seen what it claims to do.
But either they are hand-waving over a critical requirement of what it takes to repro, or it's fake.In conversation permalink -
Embed this notice
Will Dormann (wdormann@infosec.exchange)'s status on Thursday, 04-Jun-2026 23:54:13 JST
Will Dormann
@christopherkunz
Ah, so you've confirmed that it works?
With AI and clout seeking these days, we've long passed the "PoC exists on Github" thing having any meaning whatsoever. 😂Personally, I couldn't get that one to do anything.
In conversation permalink -
Embed this notice
Dr. Christopher Kunz (christopherkunz@chaos.social)'s status on Thursday, 04-Jun-2026 23:54:13 JST
Dr. Christopher Kunz
@wdormann https://chaos.social/@christopherkunz/116676523296824499
In conversation permalink Attachments
-
Embed this notice
Will Dormann (wdormann@infosec.exchange)'s status on Thursday, 04-Jun-2026 23:54:14 JST
Will Dormann
@christopherkunz
Reference?In conversation permalink -
Embed this notice
Dr. Christopher Kunz (christopherkunz@chaos.social)'s status on Thursday, 04-Jun-2026 23:54:14 JST
Dr. Christopher Kunz
@wdormann https://github.com/0xABCD01/CVE-2026-41089/blob/main/poc.py#L234
In conversation permalink Attachments
-
Embed this notice