Summary
Microsoft's Netlogon Remote Protocol (MS-NRPC) in Windows Server domain controllers contains a privilege escalation flaw in the secure-channel authentication handshake. An unauthenticated attacker with network access can repeatedly send crafted Netlogon requests, eventually impersonate the domain controller, and reset its machine account password. Successful exploitation can expose domain credentials, grant domain administrator privileges, and enable takeover of the Active Directory domain.
Why Fix Soon?
5/6Exploitation Details
Reset the domain controller machine account password and take over the Active Directory domain.
Full System CompromiseAffected Software
| Product | Affected Versions |
|---|---|
| Windows Server | 2008 R2 SP1, 2012, 2012 R2, 2016, 2019, version 1809, version 1903, version 1909 |
Microsoft's server operating system used for enterprise infrastructure such as domain controllers, identity services, file and print services, and application hosting.
Affected ComponentNetlogon secure channel authentication in the Netlogon Remote Protocol (MS-NRPC) on Active Directory domain controllers.
Netlogon secure channel authentication in the Netlogon Remote Protocol (MS-NRPC) on Active Directory domain controllers.
Set FullSecureChannelProtection=1 to enable enforcement mode early and deny vulnerable Netlogon secure channel connections except for temporary allow-list exceptions.
Set FullSecureChannelProtection=1 to enable enforcement mode early and deny vulnerable Netlogon secure channel connections except for temporary allow-list exceptions.
Not available
Install the August 11, 2020 or later Windows security updates on all domain controllers, then apply the February 9, 2021 or later updates that enable Netlogon enforcement mode by default.
Install the August 11, 2020 or later Windows security updates on all domain controllers, then apply the February 9, 2021 or later updates that enable Netlogon enforcement mode by default.
Probability of exploitation in the next 30 days
Worse than 100% of all CVEs
NVD Data
Description Summary
CVSS Base Score
CVSS Vector (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
Affected Software (CPE) (23)
- •cpe:2.3:o:microsoft:windows_server_1903:*:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_server_1909:*:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_server_2004:-:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*
- •cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:*
- •cpe:2.3:o:microsoft:windows_server_20h2:-:*:*:*:*:*:*:*
- •cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
- •cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
- •cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
- •cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*
- •cpe:2.3:o:opensuse:leap:15.2:*:*:*:*:*:*:*
- •cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*
- •cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
- •cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
- •cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
- •cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*
- •cpe:2.3:a:synology:directory_server:*:*:*:*:*:*:*:*
- •cpe:2.3:a:samba:samba:*:*:*:*:*:*:*:*
- •cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
- •cpe:2.3:a:oracle:zfs_storage_appliance_kit:8.8:*:*:*:*:*:*:*
Sources
| Source | Article |
|---|---|
| support.microsoft.com | Netlogon secure channel changes for CVE-2020-1472 |
| www.microsoft.com | Attacks exploiting Netlogon vulnerability (CVE-2020-1472) |
| www.microsoft.com | Zerologon is now detected by Microsoft Defender for Identity |
| www.microsoft.com | Behavior:Win32/CVE-2020-1472.B |
| www.cisa.gov | Microsoft Warns of Continued Exploitation of CVE-2020-1472 |
| nvd.nist.gov | CVE-2020-1472 Detail |
| www.tenable.com | CVE-2020-1472 |
| research.splunk.com | Detect Zerologon Attack |
| github.com | Secura CVE-2020-1472 |
| github.com | dirkjanm/CVE-2020-1472 |
| www.microsoft.com | Cadet Blizzard threat actor report |
Priority History
Initial analysis