Junglewise Threat Intelligence

CVE-2020-1472: Microsoft Netlogon Privilege Escalation Vulnerability

CVE-2020-1472 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2021-11-03

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

A privilege escalation vulnerability, known as Zerologon, exists in the Microsoft Netlogon Remote Protocol (MS-NRPC) when an attacker establishes a vulnerable secure channel connection to a domain controller. An unauthenticated attacker can exploit this to obtain domain administrator access and execute applications on devices within the network.

Affected products

  • Microsoft Windows
  • Microsoft Netlogon Remote Protocol (MS-NRPC)

Timeline

  • 2020-09-28: other: Updated guidelines on managing Netlogon secure channel changes published.
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2021-Q1: patched: Second phase of Windows updates made available.