TL;DR: A denial-of-service flaw in Microsoft’s Netlogon protocol lets a low-privileged, domain-joined machine crash a domain controller through a malformed authentication request, disrupting logins, policy application, and other AD-dependent services, according to Silverfort. The issue shows that availability failures in core identity services can become enterprise-wide outages when machine-account trust and protocol validation are weak.
Editorial analysis by NHI Mgmt Group, based on content published by Silverfort: “NOTLogon: How a Low-Privilege Machine Can DoS Your Domain”.
Key questions
Q: What breaks when a malformed Netlogon request reaches a domain controller?
A: A malformed request can crash LSASS, reboot the domain controller, and interrupt Active Directory services that depend on it.
A: A Netlogon flaw is dangerous because it can let an attacker on the local network change a domain controller password without valid user credentials.
Q: What signs suggest Active Directory trust paths are too exposed?
A: Warning signs include broad machine-account creation rights, direct workstation-to-domain-controller reachability, and limited monitoring of Netlogon authentication flows.
Practitioner guidance
- Patch all domain controllers immediately Apply Microsoft’s July 8, 2025 update for CVE-2025-47978 across every domain controller, then verify that no controller remains on the vulnerable Netlogon build.
- Restrict machine-account creation Remove default machine-account creation where it is not operationally required, and review which users can bind to privileged Netlogon paths.
- Limit domain-controller network reachability Segment workstations and servers so only approved administrative and authentication paths can reach domain controllers over Netlogon RPC.
Bottom line: A malformed Netlogon request can destabilise the core Windows identity service, which makes availability a first-class identity control concern.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Netlogon availability is now an identity governance issue, not just a protocol bug. The vulnerable path sits inside a core authentication broker that many organisations still treat as reliable infrastructure rather than a high-risk control plane. When LSASS crashes, directory trust becomes an outage condition and not merely a failed request. The practitioner conclusion is that availability assumptions must be enforced on identity infrastructure with the same seriousness as access policy.
A question worth separating out:
Q: How should teams balance Netlogon hardening with Active Directory uptime?
A: They should treat domain-controller exposure as a resilience question, not only a security question. Patch first, then reduce who can create machine accounts and who can reach Netlogon paths. That lowers the chance that one malformed request can take down the identity core that everything else depends on.
👉 Read our full editorial: Netlogon DoS exposure shows the fragility of active directory trust