Executive brief
A privilege escalation vulnerability, known as Zerologon, exists in the Microsoft Netlogon Remote Protocol (MS-NRPC) when an attacker establishes a vulnerable secure channel connection to a domain controller. An unauthenticated attacker can exploit this to obtain domain administrator access and execute applications on devices within the network.
Affected products
- Microsoft Windows
- Microsoft Netlogon Remote Protocol (MS-NRPC)
Timeline
- 2020-09-28: other: Updated guidelines on managing Netlogon secure channel changes published.
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2021-Q1: patched: Second phase of Windows updates made available.