Abstract illustration of connected devices separated by a protected security boundary.
Microsoft has issued a fix for CVE-2026-72982: Windows Netlogon Remote Code Execution Vulnerability, a Critical stack-based buffer overflow in Windows Netlogon. The flaw carries a CVSS base score of 9.8 and a CVSS temporal score of 8.5.

Microsoft’s advisory states: “Windows Netlogon Remote Code Execution Vulnerability: Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.”

The vulnerability is classified as CWE-121, or stack-based buffer overflow. Its CVSS vector is:

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

In plain English, the score reflects a network-reachable issue with low attack complexity, no required privileges, and no user interaction. Successful exploitation could affect confidentiality, integrity, and availability—the full CIA-triad unpleasantness administrators hope never arrives in a maintenance window.

  • Publicly disclosed: No
  • Exploited: No
  • Customer action required: Yes

Microsoft’s exploitation assessment is Exploitation Unlikely.

Abstract illustration of connected devices separated by a protected security boundary. How the Netlogon flaw could be exploited​

Microsoft says an unauthenticated attacker could target an affected service by sending a specially crafted packet over the network. If successful, the attack could enable code execution on the targeted machine.

The official advisory is explicit: “How could an attacker exploit this vulnerability? An unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required.”

That combination—remote reachability, no credentials, no click required, and potential code execution—is why the base score lands near the top of the CVSS scale. Organizations should prioritize the listed cumulative updates through their standard Windows update-management process and verify the resulting build numbers.

Affected Windows products and fixed builds​

The following products are affected by CVE-2026-72982, with the required KB and vendor fixed build for each supported configuration.

Affected productRequired update and fixed build
Windows 10 Version 1607 for 32-bit Systems (x86)For Windows 10 Version 1607 for 32-bit Systems (x86), install KB5123099 to reach fixed build 10.0.14393.9512.
Windows 10 Version 1607 for x64-based SystemsFor Windows 10 Version 1607 for x64-based Systems, install KB5123099 to reach fixed build 10.0.14393.9512.
Windows 10 Version 1809 for 32-bit Systems (x86)For Windows 10 Version 1809 for 32-bit Systems (x86), install KB5122876 to reach fixed build 10.0.17763.9245.
Windows 10 Version 1809 for x64-based SystemsFor Windows 10 Version 1809 for x64-based Systems, install KB5122876 to reach fixed build 10.0.17763.9245.
Windows 10 Version 21H2 for 32-bit Systems (x86)For Windows 10 Version 21H2 for 32-bit Systems (x86), install KB5122878 to reach fixed build 10.0.19044.7725.
Windows 10 Version 21H2 for ARM64-based SystemsFor Windows 10 Version 21H2 for ARM64-based Systems, install KB5122878 to reach fixed build 10.0.19044.7725.
Windows 10 Version 21H2 for x64-based SystemsFor Windows 10 Version 21H2 for x64-based Systems, install KB5122878 to reach fixed build 10.0.19044.7725.
Windows 10 Version 22H2 for 32-bit Systems (x86)For Windows 10 Version 22H2 for 32-bit Systems (x86), install KB5122878 to reach fixed build 10.0.19045.7725.
Windows 10 Version 22H2 for ARM64-based SystemsFor Windows 10 Version 22H2 for ARM64-based Systems, install KB5122878 to reach fixed build 10.0.19045.7725.
Windows 10 Version 22H2 for x64-based SystemsFor Windows 10 Version 22H2 for x64-based Systems, install KB5122878 to reach fixed build 10.0.19045.7725.
Windows 11 Version 23H2 for ARM64-based SystemsFor Windows 11 Version 23H2 for ARM64-based Systems, install KB5122880 to reach fixed build 10.0.22631.7582.
Windows 11 Version 23H2 for x64-based SystemsFor Windows 11 Version 23H2 for x64-based Systems, install KB5122880 to reach fixed build 10.0.22631.7582.
Windows 11 Version 24H2 for ARM64-based SystemsFor Windows 11 Version 24H2 for ARM64-based Systems, install KB5124008 to reach fixed build 10.0.26100.9445.
Windows 11 Version 24H2 for x64-based SystemsFor Windows 11 Version 24H2 for x64-based Systems, install KB5124008 to reach fixed build 10.0.26100.9445.
Windows 11 Version 25H2 for ARM64-based SystemsFor Windows 11 Version 25H2 for ARM64-based Systems, install KB5124008 to reach fixed build 10.0.26200.9445.
Windows 11 Version 25H2 for x64-based SystemsFor Windows 11 Version 25H2 for x64-based Systems, install KB5124008 to reach fixed build 10.0.26200.9445.
Windows 11 Version 26H1 for ARM64-based SystemsFor Windows 11 Version 26H1 for ARM64-based Systems, install KB5124012 to reach fixed build 10.0.28000.2954.
Windows 11 version 26H1 for x64-based SystemsFor Windows 11 version 26H1 for x64-based Systems, install KB5124012 to reach fixed build 10.0.28000.2954.
Windows Server 2012 (Server Core installation) (x64)For Windows Server 2012 (Server Core installation) (x64), install KB5123065 to reach fixed build 6.2.9200.26349.
Windows Server 2012 (x64)For Windows Server 2012 (x64), install KB5123065 to reach fixed build 6.2.9200.26349.
Windows Server 2012 R2 (Server Core installation) (x64)For Windows Server 2012 R2 (Server Core installation) (x64), install KB5123066 to reach fixed build 6.3.9600.23398.
Windows Server 2012 R2 (x64)For Windows Server 2012 R2 (x64), install KB5123066 to reach fixed build 6.3.9600.23398.
Windows Server 2016 (Server Core installation) (x64)For Windows Server 2016 (Server Core installation) (x64), install KB5123099 to reach fixed build 10.0.14393.9512.
Windows Server 2016 (x64)For Windows Server 2016 (x64), install KB5123099 to reach fixed build 10.0.14393.9512.
Windows Server 2019 (Server Core installation) (x64)For Windows Server 2019 (Server Core installation) (x64), install KB5122876 to reach fixed build 10.0.17763.9245.
Windows Server 2019 (x64)For Windows Server 2019 (x64), install KB5122876 to reach fixed build 10.0.17763.9245.
Windows Server 2022 (Server Core installation) (x64)For Windows Server 2022 (Server Core installation) (x64), install KB5122882 to reach fixed build 10.0.20348.5622.
Windows Server 2022 (x64)For Windows Server 2022 (x64), install KB5122882 to reach fixed build 10.0.20348.5622.
Windows Server 2025 (Server Core installation) (x64)For Windows Server 2025 (Server Core installation) (x64), install KB5122871 to reach fixed build 10.0.26100.33438.
Windows Server 2025 (x64)For Windows Server 2025 (x64), install KB5122871 to reach fixed build 10.0.26100.33438.

Practical administrator checklist​

  1. Identify Windows clients and servers that match the affected product list.
  2. Deploy the applicable cumulative update through the organization’s approved patching workflow.
  3. Restart systems when the update process requires it.
  4. Confirm the post-update build number matches the fixed build assigned to that product and architecture.
  5. Treat server systems with reachable Netlogon services as a priority for remediation planning, given the network-based attack path described in Microsoft’s advisory.

CVE-2026-72982 is a case where the remediation instruction is admirably boring: install the applicable update and confirm the build. In security, boring is often the most beautiful word in the dictionary.

 

References

  1. Official MSRC or vendor evidence api.msrc.microsoft.com
  2. Official MSRC or vendor evidence msrc.microsoft.com
  3. Official MSRC or vendor evidence api.msrc.microsoft.com