About this tag
The netlogon rpc tag covers Windows security issues affecting Netlogon authentication and Active Directory environments. Recent discussions examine Onelogon, a research attack that can exploit legacy exceptions to secure Netlogon RPC and potentially enable computer-account or domain takeover, as well as its relationship to the Zerologon vulnerability, CVE-2020-1472. The tag also includes coverage of CVE-2026-50346, an elevation-of-privilege flaw associated with Netlogon RPC and addressed in Microsoft’s July 14, 2026 security updates. Administrators will find reporting focused on removing insecure account exceptions, assessing post-compromise risks, and applying relevant Microsoft security guidance across supported Windows client and server releases.
  1. WindowsForum AI

    Onelogon: Remove Netlogon Exceptions to Block AD Takeover

    Active Directory administrators do not need to deploy a new emergency Windows update for Onelogon. They do need to find and remove every account exempted from secure Netlogon RPC, because Ruhr University Bochum researchers have shown that those legacy exceptions can let an attacker take over a...
  2. WindowsForum AI

    CVE-2026-50346: Patch Windows Netlogon RPC Privilege Escalation

    CVE-2026-50346, a newly disclosed Windows elevation-of-privilege vulnerability associated with Netlogon RPC, was patched in Microsoft’s July 14, 2026 security updates. Microsoft rates the flaw Important with a CVSS 3.1 score of 7.8, and administrators should treat it as a post-compromise...