Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
widely-deployed-product-advisoryendpoint-software-vulnerabilitycloud-service-vulnerabilityinternet-facing-service-vulnerability

Microsoft Patches 137 Flaws, Highlighting Word Preview Pane and Netlogon RCE Risks

Updated 28d agoFirst seen Apr 14, 202689 sources

Microsoft released its May Patch Tuesday updates fixing 137 vulnerabilities across Windows, Office, Azure, Dynamics 365, SharePoint, Copilot, and other products, with no actively exploited zero-days or publicly disclosed flaws reported at release. The update included multiple high-severity remote code execution bugs, notably Microsoft Word flaws CVE-2026-40361 and CVE-2026-40364, which can be triggered through the Preview Pane by sending a malicious document, as well as CVE-2026-42898 in Microsoft Dynamics 365 On-Premises, CVE-2026-42823 in Azure Logic Apps, and CVE-2026-33109 in Azure Managed Instance for Apache Cassandra. Researchers also flagged CVE-2026-41089 in Windows Netlogon and CVE-2026-41096 in Windows DNS Client as especially urgent because they expose broadly deployed enterprise infrastructure to remote compromise.

Microsoft’s Windows 11 cumulative updates, including KB5089549 and KB5087420, delivered many of the security fixes alongside reliability and usability improvements, and Microsoft said it was not aware of new issues with the release. Coverage and advisories also showed the breadth of the month’s attack surface, with additional fixes for SharePoint Server remote code execution, Office Click-to-Run privilege escalation, Hyper-V guest-to-host escalation, Teams spoofing, Outlook for iOS tampering, and several Copilot and Visual Studio Code vulnerabilities. Security researchers said the growing volume of Microsoft disclosures may reflect increased AI-assisted vulnerability discovery, while defenders were urged to prioritize patching domain controllers, DNS-exposed Windows systems, Office deployments, and internet-facing enterprise applications.

Share:
Microsoft Patches 137 Flaws, Highlighting Word Preview Pane and Netlogon RCE Risks
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

33 events from the most recent confirmed update back to the earliest known activity.

33 EVENTS
May 21, 20261mo ago

Microsoft publishes CVE-2026-42534 for Jostle logic bypass issue

On 2026-05-21, Microsoft published Security Update Guide entry CVE-2026-42534, described as a Jostle logic bypass vulnerability that degrades resolution performance. This is a newly documented Microsoft flaw not previously captured in the timeline.

CVE-2026-42534 - Security Update Guide - Microsoft - Jostle logic bypass degrades resolution performance

Microsoft publishes CVE-2026-42827 for M365 Copilot information disclosure

On 2026-05-21, Microsoft published Security Update Guide entry CVE-2026-42827, an information disclosure vulnerability affecting M365 Copilot. This appears to be a newly documented Microsoft flaw not previously identified in the existing timeline.

CVE-2026-42827 - Security Update Guide - Microsoft - M365 Copilot Information Disclosure Vulnerability
May 19, 20261mo ago

Microsoft discloses CVE-2026-42834 in Windows Admin Center in Azure Portal

On 2026-05-19, Microsoft published Security Update Guide entry CVE-2026-42834, an elevation-of-privilege vulnerability affecting Windows Admin Center in Azure Portal. This added a specific newly documented Microsoft flaw not previously called out in the existing timeline.

CVE-2026-42834 - Security Update Guide - Microsoft - Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability
May 12, 20261mo ago

Microsoft discloses Windows Event Logging Service EoP flaw CVE-2026-33834

On 2026-05-12, Microsoft published CVE-2026-33834, an Important elevation-of-privilege vulnerability in the Windows Event Logging Service caused by improper access control. The local flaw could let a low-privileged authorized attacker gain SYSTEM privileges without user interaction; Microsoft said a fix was available, exploitation was considered less likely, and the bug was neither publicly disclosed nor exploited at release.

CVE-2026-33834 - Security Update Guide - Microsoft - Windows Event Logging Service Elevation of Privilege Vulnerability

Microsoft discloses Office RCE flaw CVE-2026-40363

On 2026-05-12, Microsoft published CVE-2026-40363, a Critical Microsoft Office remote code execution vulnerability caused by a heap-based buffer overflow. Microsoft said the flaw can be exploited via a local attack vector and that the Preview Pane is an attack vector; a fix was available and the bug was neither publicly disclosed nor exploited at release.

CVE-2026-40363 - Security Update Guide - Microsoft - Microsoft Office Remote Code Execution Vulnerability

Microsoft discloses Win32k EoP flaw CVE-2026-33839

On 2026-05-12, Microsoft published CVE-2026-33839, an Important elevation-of-privilege vulnerability in Windows Win32K - GRFX caused by a race condition. The local flaw could allow an authorized low-privileged attacker to obtain SYSTEM privileges without user interaction if they win the race condition; Microsoft said a fix was available and that the bug was neither publicly disclosed nor exploited at release.

CVE-2026-33839 - Security Update Guide - Microsoft - Win32k Elevation of Privilege Vulnerability

Microsoft discloses Win32k EoP flaw CVE-2026-34333

On 2026-05-12, Microsoft published CVE-2026-34333, an Important elevation-of-privilege vulnerability in Windows Win32K-GRFX caused by use-after-free and integer overflow or wraparound conditions. The local flaw could let a low-privileged authorized attacker gain SYSTEM privileges without user interaction; Microsoft said a fix was available and that the bug was neither publicly disclosed nor exploited at release.

CVE-2026-34333 - Security Update Guide - Microsoft - Windows Win32k Elevation of Privilege Vulnerability

Microsoft discloses Win32k EoP flaw CVE-2026-34330

On 2026-05-12, Microsoft published CVE-2026-34330, an Important elevation-of-privilege vulnerability in Windows Win32K - GRFX caused by integer overflow or wraparound and use-after-free conditions. The local flaw could let a low-privileged authorized attacker gain SYSTEM privileges; Microsoft said a fix was available and that the bug was neither publicly disclosed nor exploited at release.

CVE-2026-34330 - Security Update Guide - Microsoft - Win32k Elevation of Privilege Vulnerability

Microsoft discloses WinSock driver EoP flaw CVE-2026-41088

On 2026-05-12, Microsoft published CVE-2026-41088, an Important elevation-of-privilege vulnerability in the Windows Ancillary Function Driver for WinSock caused by external control of a file name or path. The local flaw could let a low-privileged authorized attacker gain SYSTEM privileges without user interaction; Microsoft said a fix was available and that the bug was neither publicly disclosed nor exploited at release.

CVE-2026-41088 - Security Update Guide - Microsoft - Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

Microsoft discloses Windows CLFS Driver EoP flaw CVE-2026-40397

On 2026-05-12, Microsoft published CVE-2026-40397, an Important elevation-of-privilege vulnerability in the Windows Common Log File System Driver caused by an integer underflow. The local flaw could let a low-privileged attacker gain SYSTEM privileges without user interaction; Microsoft said a fix was available, exploitation was considered more likely, and the bug was neither publicly disclosed nor exploited at release.

CVE-2026-40397 - Security Update Guide - Microsoft - Windows Common Log File System Driver Elevation of Privilege Vulnerability

Microsoft discloses PowerPoint spoofing flaw CVE-2026-41102

On 2026-05-12, Microsoft published CVE-2026-41102, an Important spoofing vulnerability affecting Microsoft PowerPoint for Android and Microsoft Office PowerPoint caused by improper access control. Microsoft said the local flaw could be exploited by a low-privileged authorized attacker without user interaction, that a fix was available, and that the bug was neither publicly disclosed nor exploited at release.

CVE-2026-41102 - Security Update Guide - Microsoft - Microsoft PowerPoint for Android Spoofing Vulnerability

Microsoft discloses Copilot for Android spoofing flaw CVE-2026-41100

On 2026-05-12, Microsoft published CVE-2026-41100, an Important spoofing vulnerability affecting Microsoft 365 Copilot for Android caused by improper access control. Microsoft said the local flaw could be exploited by a low-privileged authorized attacker without user interaction, that a fix was available, and that the bug was neither publicly disclosed nor exploited at release.

CVE-2026-41100 - Security Update Guide - Microsoft - Microsoft 365 Copilot for Android Spoofing Vulnerability

Microsoft discloses Windows TCP/IP EoP flaw CVE-2026-34334

On 2026-05-12, Microsoft published CVE-2026-34334, an Important elevation-of-privilege vulnerability in Windows TCP/IP caused by a race condition. The local flaw could allow a low-privileged authorized attacker to gain SYSTEM privileges without user interaction; Microsoft said a fix was available and that the bug was neither publicly disclosed nor exploited at release.

CVE-2026-34334 - Security Update Guide - Microsoft - Windows TCP/IP Elevation of Privilege Vulnerability

Microsoft discloses Windows Cloud Files Mini Filter Driver EoP flaw CVE-2026-33835

On 2026-05-12, Microsoft published CVE-2026-33835, an Important elevation-of-privilege vulnerability in the Windows Cloud Files Mini Filter Driver caused by a use-after-free flaw. The local bug could let a low-privileged attacker gain SYSTEM privileges without user interaction; Microsoft said a fix was available, exploitation was considered more likely, and the flaw was neither publicly disclosed nor exploited at release.

CVE-2026-33835 - Security Update Guide - Microsoft - Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

Microsoft discloses Excel information disclosure flaw CVE-2026-40360

On 2026-05-12, Microsoft published CVE-2026-40360, an Important Microsoft Excel information disclosure vulnerability caused by an out-of-bounds read. The flaw can let an unauthorized attacker read small portions of heap memory if a user opens a malicious Office file; Microsoft said the Preview Pane is not an attack vector, a fix was available, and the bug was neither publicly disclosed nor exploited at release.

CVE-2026-40360 - Security Update Guide - Microsoft - Microsoft Excel Information Disclosure Vulnerability

Microsoft discloses Windows Kernel EoP flaw CVE-2026-40369

On 2026-05-12, Microsoft published CVE-2026-40369, an Important Windows Kernel elevation-of-privilege vulnerability caused by an untrusted pointer dereference. The local flaw could let a low-privileged attacker gain limited SYSTEM privileges without user interaction; Microsoft said a fix was available, exploitation was considered more likely, and the bug was neither publicly disclosed nor exploited at release.

CVE-2026-40369 - Security Update Guide - Microsoft - Windows Kernel Elevation of Privilege Vulnerability

Microsoft discloses Windows Kernel EoP flaw CVE-2026-35420

On 2026-05-12, Microsoft published CVE-2026-35420, an Important Windows Kernel elevation-of-privilege vulnerability caused by a heap-based buffer overflow. The local flaw could let a low-privileged attacker gain SYSTEM privileges without user interaction; Microsoft said a fix was available and that the bug was neither publicly disclosed nor exploited at release.

CVE-2026-35420 - Security Update Guide - Microsoft - Windows Kernel Elevation of Privilege Vulnerability

Microsoft discloses Windows Kernel EoP flaw CVE-2026-33841

On 2026-05-12, Microsoft published CVE-2026-33841, an Important Windows Kernel elevation-of-privilege vulnerability caused by a heap-based buffer overflow. The local flaw could let a low-privileged attacker escape a low-integrity sandbox and elevate to Medium or High Integrity Level; Microsoft said a fix was available and that the bug was neither publicly disclosed nor exploited at release.

CVE-2026-33841 - Security Update Guide - Microsoft - Windows Kernel Elevation of Privilege Vulnerability

Microsoft discloses Windows Telephony Service EoP flaw CVE-2026-34338

On 2026-05-12, Microsoft published CVE-2026-34338, an Important elevation-of-privilege vulnerability in Windows Telephony Service caused by a use-after-free flaw. The local bug could let a low-privileged attacker gain SYSTEM privileges without user interaction; Microsoft said a fix was available and that the flaw was neither publicly disclosed nor exploited at release.

CVE-2026-34338 - Security Update Guide - Microsoft - Windows Telephony Service Elevation of Privilege Vulnerability

Microsoft discloses Windows Telephony Service EoP flaw CVE-2026-40382

On 2026-05-12, Microsoft published CVE-2026-40382, an Important elevation-of-privilege vulnerability in Windows Telephony Service caused by a use-after-free flaw. The local bug could let a low-privileged attacker gain SYSTEM privileges without user interaction; Microsoft said it was neither publicly disclosed nor exploited at release and assessed exploitation as less likely.

CVE-2026-40382 - Security Update Guide - Microsoft - Windows Telephony Service Elevation of Privilege Vulnerability

Microsoft discloses Windows Rich Text Edit EoP flaw CVE-2026-32170

On 2026-05-12, Microsoft published CVE-2026-32170, an Important elevation-of-privilege vulnerability in the Windows Rich Text Edit Control caused by a double-free weakness. Microsoft said exploitation requires local access, low privileges, user interaction, and winning a race condition; a fix was available and the flaw was neither publicly disclosed nor exploited at release.

CVE-2026-32170 - Security Update Guide - Microsoft - Windows Rich Text Edit Elevation of Privilege Vulnerability

Microsoft discloses Dynamics 365 Business Central EoP flaw CVE-2026-40417

On 2026-05-12, Microsoft published CVE-2026-40417, an Important elevation-of-privilege vulnerability in Microsoft Dynamics 365 Business Central caused by weak authentication. The local flaw could allow a low-privileged authorized attacker to gain SYSTEM privileges without user interaction; Microsoft said a fix was available and that the bug was neither publicly disclosed nor exploited at release.

CVE-2026-40417 - Security Update Guide - Microsoft - Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability

Microsoft discloses Azure ML Notebook spoofing flaw CVE-2026-33833

On 2026-05-12, Microsoft published CVE-2026-33833, an Important spoofing vulnerability affecting Azure Machine Learning notebooks. The network-exploitable flaw could be triggered if a user opens or views a malicious notebook in the Azure ML web interface, potentially exposing sensitive information; Microsoft said a fix was available and that the bug was neither publicly disclosed nor exploited at release.

CVE-2026-33833 - Security Update Guide - Microsoft - Azure Machine Learning Notebook Spoofing Vulnerability

Microsoft discloses Office Click-To-Run EoP flaw CVE-2026-40418

On 2026-05-12, Microsoft published CVE-2026-40418, an Important elevation-of-privilege vulnerability in Microsoft Office Click-To-Run caused by a use-after-free flaw. The local bug could let a low-privileged authorized attacker gain SYSTEM privileges without user interaction; Microsoft said a fix was available and that the flaw was neither publicly disclosed nor exploited at release.

CVE-2026-40418 - Security Update Guide - Microsoft - Microsoft Office Click-To-Run Elevation of Privilege Vulnerability

Microsoft discloses Office Click-To-Run EoP flaw CVE-2026-35436

On 2026-05-12, Microsoft published CVE-2026-35436, an Important elevation-of-privilege vulnerability in Microsoft Office Click-To-Run caused by insufficient access control granularity. The local flaw could let a low-privileged authorized attacker gain SYSTEM privileges; Microsoft said a fix was available and that the bug was neither publicly disclosed nor exploited at release.

CVE-2026-35436 - Security Update Guide - Microsoft - Microsoft Office Click-To-Run Elevation of Privilege Vulnerability

Talos releases Snort coverage for May 2026 Microsoft vulnerabilities

On 2026-05-12, Cisco Talos published analysis of Microsoft's May 2026 Patch Tuesday and released Snort 2 and Snort 3 rules to help detect exploitation attempts against some of the disclosed vulnerabilities. Talos highlighted numerous critical remote code execution issues and several elevation-of-privilege flaws considered more likely to be exploited.

Microsoft publishes May 2026 Windows 11 cumulative updates

On 2026-05-12, Microsoft released Windows 11 cumulative updates KB5089549 for versions 25H2/24H2 and KB5087420 for version 23H2. The mandatory updates included security fixes tied to the May Patch Tuesday release and additional reliability, usability, and performance improvements across core Windows components.

Microsoft fixes critical enterprise flaws in Dynamics 365, Azure, Netlogon and DNS

The 2026-05-12 Patch Tuesday also remediated several especially dangerous enterprise vulnerabilities, including Dynamics 365 On-Premises RCE CVE-2026-42898, Azure Logic Apps EoP CVE-2026-42823, Azure Managed Instance for Apache Cassandra RCE CVE-2026-33109, Windows Netlogon RCE CVE-2026-41089, and Windows DNS Client RCE CVE-2026-41096. Researchers warned these bugs could enable broad compromise of enterprise environments and domain controllers if left unpatched.

Microsoft patches high-risk Word Preview Pane RCE flaws

As part of the 2026-05-12 release, Microsoft fixed Microsoft Word remote code execution vulnerabilities including CVE-2026-40361 and CVE-2026-40364 that can be triggered through the Preview Pane by sending a malicious document, requiring no file opening by the victim. Coverage highlighted these flaws as among the most urgent issues in the release.

Microsoft issues May 2026 Patch Tuesday covering 137 vulnerabilities

On 2026-05-12, Microsoft released its May 2026 Patch Tuesday updates, fixing 137 vulnerabilities across Windows, Office, Azure, Dynamics 365, SharePoint, Copilot, and other products. Multiple reports noted this was the first Patch Tuesday in nearly two years with no actively exploited zero-days or previously disclosed flaws at release time.

May 7, 20262mo ago

Microsoft discloses Dynamics 365 Customer Insights EoP flaw CVE-2026-33821

On 2026-05-07, Microsoft published Security Update Guide entry CVE-2026-33821, an elevation-of-privilege vulnerability affecting Microsoft Dynamics 365 Customer Insights. This is a newly documented Microsoft flaw not previously captured in the timeline.

CVE-2026-33821 - Security Update Guide - Microsoft - Microsoft Dynamics 365 Customer Insights Elevation of Privilege Vulnerability

Microsoft discloses M365 Copilot info disclosure flaw CVE-2026-26129

On 2026-05-07, Microsoft published CVE-2026-26129, a Critical information disclosure vulnerability affecting M365 Copilot caused by improper neutralization of special elements. Microsoft said the network-exploitable issue was fully mitigated with no customer action required and was neither publicly disclosed nor exploited at publication.

CVE-2026-26129 - Security Update Guide - Microsoft - M365 Copilot Information Disclosure Vulnerability
Apr 14, 20262mo ago

Microsoft releases April 2026 Patch Tuesday with one exploited SharePoint flaw

On 2026-04-14, Microsoft's April 2026 Patch Tuesday addressed 165 vulnerabilities, including eight rated critical. Microsoft disclosed that SharePoint spoofing flaw CVE-2026-32201 had already been exploited in the wild, and Talos published Snort detection rules for the release.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

94 LINKEDOpen in app
Vulnerabilities
60 linked
Windows Netlogon Remote Code Execution VulnerabilityRemote Code Execution in Azure Managed Instance for Apache CassandraRemote Code Execution in Microsoft Dynamics 365 On-PremisesMicrosoft Word Preview Pane Use-After-Free Remote Code ExecutionWindows DNS Client Remote Code Execution VulnerabilityMicrosoft Word Preview Pane Type Confusion RCEPrivilege Escalation in Azure Logic AppsWindows Remote Desktop RDP File Spoofing VulnerabilityBlueHammer - TOCTOU LPE in Microsoft Defender signature update workflow.NET Framework Denial of Service VulnerabilityWindows UPnP Device Host Elevation of Privilege VulnerabilityWindows Active Directory Remote Code Execution VulnerabilityWindows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityMicrosoft Word Use-After-Free Remote Code Execution VulnerabilityDesktop Window Manager Elevation of Privilege VulnerabilityWindows Hello Security Feature BypassMicrosoft SharePoint Server Spoofing VulnerabilityWindows Kernel Memory Information Disclosure VulnerabilityWindows BitLocker Secure Boot Security Feature BypassWindows Search Service Elevation of Privilege VulnerabilityWindows TCP/IP Remote Code Execution VulnerabilityWindows COM Elevation of Privilege VulnerabilityWindows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityUEFI Secure Boot Security Feature Bypass in Windows Boot LoaderWindows Common Log File System Driver Use-After-Free Elevation of PrivilegeWindows Shell Zero-Click Authentication Coercion / Spoofing VulnerabilityMicrosoft Office Use-After-Free Remote Code Execution VulnerabilityWindows Function Discovery Service (fdwsd.dll) Elevation of Privilege VulnerabilityMicrosoft Word Untrusted Pointer Dereference Remote Code Execution VulnerabilityWindows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityWindows TDI Translation Driver (tdx.sys) Elevation of Privilege VulnerabilityDesktop Window Manager Elevation of Privilege VulnerabilityWindows Shell SmartScreen/MotW Security Feature BypassWindows Internet Key Exchange (IKE) Service Extensions IKEv2 Double-Free Remote Code ExecutionDesktop Window Manager Use-After-Free Elevation of PrivilegeWindows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityRemote Desktop Client Use-After-Free Remote Code ExecutionWindows TDI Translation Driver (tdx.sys) Elevation of Privilege VulnerabilityMicrosoft Management Console Mark-of-the-Web Bypass Elevation of PrivilegeRemote Code Execution in Azure Managed Instance for Apache CassandraAdjacent Network RCE in Windows Native WiFi Miniport DriverMicrosoft Office Heap-Based Buffer Overflow Remote Code Execution VulnerabilityWindows Cloud Files Mini Filter Driver Elevation of Privilege VulnerabilityWindows Kernel Elevation of Privilege via NtQuerySystemInformation Class 253Remote Code Execution in Microsoft Office / Office for Android via Heap-Based Buffer OverflowWindows Remote Desktop Services Elevation of Privilege VulnerabilityWindows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityUse-After-Free Privilege Escalation in Windows Hyper-VMicrosoft Office Use-After-Free Remote Code Execution VulnerabilityMicrosoft Word Remote Code Execution Vulnerability.NET Windows Desktop Runtime Local Elevation of PrivilegeWindows GDI EMF Heap Buffer Overflow RCEWindows TCP/IP Local Elevation of Privilege VulnerabilityWindows Win32K - ICOMP Type Confusion Elevation of PrivilegeWin32k Elevation of Privilege Vulnerability in Windows Win32K - ICOMPWindows Common Log File System Driver Elevation of Privilege VulnerabilityMicrosoft Word Untrusted Pointer Dereference Local Code Execution VulnerabilityMicrosoft SharePoint Server Remote Code Execution VulnerabilityWindows Win32K-GRFX Heap-Based Buffer Overflow RCE / VM EscapeWindows Kernel Elevation of Privilege Vulnerability
Affected products
20 linked
Azure Managed Instance For Apache CassandraWindows HelloMicrosoft OfficeSnortMicrosoft Office WordWindows 11Windows ServerRemote Desktop ClientAzure Logic Apps.Net FrameworkRemote DesktopWindows KernelWindows Active DirectoryDesktop Window ManagerWindows ShellWindows BitlockerCopilotAzure Ai FoundryHyper-VMicrosoft Defender
Organizations
14 linked
Microsoft CorporationAutomoxTrend MicroCisco SystemsTenableAction1LogitechCohesityASUSCisco SystemsComputerworldFortraMicro-Star InternationalSnort.org
SOURCE COVERAGE

Sources

50 references tracked. Mallory keeps watching after this page renders.

50 SOURCESView all
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Microsoft Patches 137 Flaws, Highlighting Word Preview Pane and Netlogon RCE Risks | Mallory