This repository provides tools for security professionals and system administrators to analyze the CVE-2026-41089 vulnerability. This flaw affects the Windows Netlogon service on Domain Controllers. The software allows you to test network configurations and identify systems that carry this security risk.
Follow these steps to obtain and use the testing software. You do not need to read code or manage complex settings to run these tests on a Windows machine.
This software performs read-only checks on your network environment to verify if the server version matches the criteria for this specific critical vulnerability.
Ensure your environment meets these standards before you run the application. Use these settings for stable performance:
The tool operates through a command-line interface. While it looks like a black window with text, you only need to provide basic information when asked.
After you start the program, it will ask for the IP address or the hostname of the Domain Controller you wish to check. Type the information into the box and press the Enter key.
The software will then send a specific signal to the service to see if it responds to the flaw. It will display a clear result on your screen. A positive result indicates that the system is open to the attack and requires an update from Microsoft as soon as possible. A negative result means the system does not show signs of this vulnerability.
This tool is for educational and audit purposes only. Use it on systems you own or have explicit permission to test. Unauthorized scanning of networks may break company policy or law. Keep your operating system updated with the latest patches provided by the vendor to prevent remote code execution.
If the tool finds the vulnerability, close the application, disconnect the vulnerable controller from the primary network, and apply the official security patches immediately. Do not share your scan results with people outside your authorized security team.
If the application logs an error, verify these common fixes:
The Netlogon service handles communication between a client and a domain controller. This vulnerability stems from an error in how the service manages buffer size during authentication requests. By sending a crafted packet, an actor might force the service to run unauthorized commands. This tool simulates these packets to identify if the target system fails to sanitize input correctly. This analysis helps you determine which servers need immediate attention.
Keywords: active-directory, buffer-overflow, cve-2026-41089, cybersecurity, domain-controller, exploit-poc, netlogon-rce, privilege-escalation, remote-code-execution, threat-hunting, windows-security, zero-day