Microsoft Windows Netlogon是美国微软(Microsoft)公司的Windows的一个重要组件,主要功能是用户和机器在域内网络上的认证,以及复制数据库以进行域控备份,同时还用于维护域成员与域之间、域与域控之间、域DC与跨域DC之间的关系。 Microsoft Windows Netlogon存在安全漏洞。攻击者利用该漏洞可以远程执行代码。以下产品和版本受到影响:Windows Server 2016,Windows Server 2016 (Server Core installa
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Microsoft | Windows Server 2012 | 6.2.9200.0 ~ 6.2.9200.26079 | - |
|
| Microsoft | Windows Server 2012 (Server Core installation) | 6.2.9200.0 ~ 6.2.9200.26079 | - |
|
| Microsoft | Windows Server 2012 R2 | 6.3.9600.0 ~ 6.3.9600.23181 | - |
|
| Microsoft | Windows Server 2012 R2 (Server Core installation) | 6.3.9600.0 ~ 6.3.9600.23181 | - |
|
| Microsoft | Windows Server 2016 | 10.0.14393.0 ~ 10.0.14393.9140 | - |
|
| Microsoft | Windows Server 2016 (Server Core installation) | 10.0.14393.0 ~ 10.0.14393.9140 | - |
|
| Microsoft | Windows Server 2019 | 10.0.17763.0 ~ 10.0.17763.8755 | - |
|
| Microsoft | Windows Server 2019 (Server Core installation) | 10.0.17763.0 ~ 10.0.17763.8755 | - |
|
| Microsoft | Windows Server 2022 | 10.0.20348.0 ~ 10.0.20348.5139 | - |
|
| Microsoft | Windows Server 2022, 23H2 Edition (Server Core installation) | 10.0.25398.0 ~ 10.0.25398.2330 | - |
|
| Microsoft | Windows Server 2025 | 10.0.26100.0 ~ 10.0.26100.32860 | - |
|
| Microsoft | Windows Server 2025 (Server Core installation) | 10.0.26100.0 ~ 10.0.26100.32860 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-42898 | 9.9 CRITICAL | Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability |
| CVE-2026-42823 | 9.9 CRITICAL | Azure Logic Apps Elevation of Privilege Vulnerability |
| CVE-2026-41096 | 9.8 CRITICAL | Windows DNS Client Remote Code Execution Vulnerability |
| CVE-2026-40379 | 9.3 CRITICAL | Azure Entra ID Spoofing Vulnerability |
| CVE-2026-40402 | 9.3 CRITICAL | Windows Hyper-V Elevation of Privilege Vulnerability |
| CVE-2026-42833 | 9.1 CRITICAL | Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability |
| CVE-2026-33117 | 9.1 CRITICAL | Azure SDK for Java Security Feature Bypass Vulnerability |
| CVE-2026-41103 | 9.1 CRITICAL | Microsoft SSO Plugin for Jira & Confluence Elevation of Privilege Vulnerability |
| CVE-2026-41613 | 8.8 HIGH | Visual Studio Code Elevation of Privilege Vulnerability |
| CVE-2026-35436 | 8.8 HIGH | Microsoft Office Click-To-Run Elevation of Privilege Vulnerability |
| CVE-2026-40357 | 8.8 HIGH | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2026-41094 | 8.8 HIGH | Microsoft Data Formulator Remote Code Execution Vulnerability |
| CVE-2026-41109 | 8.8 HIGH | GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability |
| CVE-2026-40420 | 8.8 HIGH | Microsoft Office Click-To-Run Elevation of Privilege Vulnerability |
| CVE-2026-40403 | 8.8 HIGH | Windows Graphics Component Remote Code Execution Vulnerability |
| CVE-2026-40370 | 8.8 HIGH | SQL Server Remote Code Execution Vulnerability |
| CVE-2026-41086 | 8.8 HIGH | Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability |
| CVE-2026-35439 | 8.8 HIGH | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2026-33112 | 8.8 HIGH | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2026-34329 | 8.8 HIGH | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability |
Showing top 20 of 125 CVEs. View all on vendor page → →
No comments yet