Skip to content

// #segmentation

1 article

🏛️ Architecture

Domain Controller Network Architecture: How DC Placement Determines Netlogon Attack Surface

CVE-2026-41089's exploitability in a given environment is almost entirely determined by which networks can reach domain controllers on TCP 445. DC placement decisions — made during infrastructure design, sometimes years ago — directly determine how many machines a Netlogon-class vulnerability exposes. Reviewing DC reachability is the highest-leverage response.

#domain-controller +7