CVE Feed

    Dashboard / CVE / CVE-2020-1472

    CVE-2020-1472

    An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run a specially crafted application on a device on the network. To exploit the vulnerability, an unauthenticated attacker would be required to use MS-NRPC to connect to a domain controller to obtain domain administrator access. Microsoft is addressing the vulnerability in a phased two-part rollout. These updates address the vulnerability by modifying how Netlogon handles the usage of Netlogon secure channels. For guidelines on how to manage the changes required for this vulnerability and more information on the phased rollout, see How to manage the changes in Netlogon secure channel connections associated with CVE-2020-1472 (updated September 28, 2020). When the second phase of Windows updates become available in Q1 2021, customers will be notified via a revision to this security vulnerability. If you wish to be notified when these updates are released, we recommend that you register for the security notifications mailer to be alerted of content changes to this advisory. See Microsoft Technical Security Notifications.

    Published:Aug 17, 2020
    Last Modified:Feb 23, 2026
    EPS:Aug 17, 2020
    EPSS Score:0.9438
    CVSS Score:5.5

    CISA Notification

    Description

    An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run a specially crafted application on a device on the network. To exploit the vulnerability, an unauthenticated attacker would be required to use MS-NRPC to connect to a domain controller to obtain domain administrator access. Microsoft is addressing the vulnerability in a phased two-part rollout. These updates address the vulnerability by modifying how Netlogon handles the usage of Netlogon secure channels. For guidelines on how to manage the changes required for this vulnerability and more information on the phased rollout, see How to manage the changes in Netlogon secure channel connections associated with CVE-2020-1472 (updated September 28, 2020). When the second phase of Windows updates become available in Q1 2021, customers will be notified via a revision to this security vulnerability. If you wish to be notified when these updates are released, we recommend that you register for the security notifications mailer to be alerted of content changes to this advisory. See Microsoft Technical Security Notifications.

    Required Action:

    Apply updates per vendor instructions.

    Notes:

    No extra notes provided.

    Due Date
    May 3, 2022
    1592 days ago
    Alert Date
    Nov 3, 2021
    1773 days ago

    Affected Products

    Vendor
    Canonical
    Product
    Ubuntu Linux
    Vendor
    Debian
    Product
    Debian Linux
    Vendor
    Fedoraproject
    Product
    Fedora
    Vendor
    Microsoft
    Product
    Windows Server 1903
    Vendor
    Microsoft
    Product
    Windows Server 1909
    Vendor
    Microsoft
    Product
    Windows Server 2004
    Vendor
    Microsoft
    Product
    Windows Server 2008
    Vendor
    Microsoft
    Product
    Windows Server 2008 R2
    Vendor
    Microsoft
    Product
    Windows Server 2012
    Vendor
    Microsoft
    Product
    Windows Server 2012 R2
    Vendor
    Microsoft
    Product
    Windows Server 2016
    Vendor
    Microsoft
    Product
    Windows Server 2019
    Vendor
    Microsoft
    Product
    Windows Server 20H2
    Vendor
    Microsoft
    Product
    Windows Server 20h2
    Vendor
    Opensuse
    Product
    Leap
    Vendor
    Oracle
    Product
    Zfs Storage Appliance Kit
    Vendor
    Redhat
    Product
    Enterprise Linux
    Vendor
    Redhat
    Product
    Storage
    Vendor
    Samba
    Product
    Samba
    Vendor
    Synology
    Product
    Directory Server

    Exploits

    http://packetstormsecurity.com/files/160127/Zerologon-Netlogon-Privilege-Escalation.htmlhttp://packetstormsecurity.com/files/160127/Zerologon-Netlogon-Privilege-Escalation.htmlhttps://www.exploit-db.com/exploits/49071https://github.com/0xcccc666/cve-2020-1472_Tool-collectionhttps://github.com/0xkami/CVE-2020-1472https://github.com/100HnoMeuNome/ZeroLogon-CVE-2020-1472-labhttps://github.com/abdullah50i/internal-penetration-testing-project-using-Metasploithttps://github.com/Akash7350/CVE-2020-1472https://github.com/Anonymous-Family/CVE-2020-1472https://github.com/Anonymous-Family/Zero-day-scanninghttps://github.com/b1ack0wl/CVE-2020-1472https://github.com/B34MR/zeroscanhttps://github.com/bb00/zer0dumphttps://github.com/blackh00d/zerologon-pochttps://github.com/bvcyber/CVE-2020-1472https://github.com/c3rrberu5/ZeroLogon-to-Shellhttps://github.com/CanciuCostin/CVE-2020-1472https://github.com/carlos55ml/zerologonhttps://github.com/ckq7703/CVE-2020-1472https://github.com/commit2main/zerologon-labhttps://github.com/CPO-EH/CVE-2020-1472_ZeroLogonCheckerhttps://github.com/cube0x0/CVE-2020-1472https://github.com/dirkjanm/CVE-2020-1472https://github.com/dr4g0n23/CVE-2020-1472https://github.com/Fa1c0n35/CVE-2020-1472https://github.com/Fa1c0n35/CVE-2020-1472-02-https://github.com/Fa1c0n35/SecuraBV-CVE-2020-1472https://github.com/FaFcFF41/CVE-2020-1472https://github.com/grupooruss/CVE-2020-1472https://github.com/guglia001/MassZeroLogonhttps://github.com/hectorgie/CVE-2020-1472https://github.com/hell-moon/ZeroLogon-Exploithttps://github.com/itssmikefm/CVE-2020-1472https://github.com/JayP232/The_big_Zerohttps://github.com/JeNilSE/CVE-2020-1472-ZeroLogon-Analysishttps://github.com/jiushill/CVE-2020-1472https://github.com/johnpathe/zerologon-cve-2020-1472-noteshttps://github.com/JolynNgSC/Zerologon_CVE-2020-1472https://github.com/k8gege/CVE-2020-1472-EXPhttps://github.com/Ken-Abruzzi/cve-2020-1472https://github.com/likeww/MassZeroLogonhttps://github.com/logg-1/0logonhttps://github.com/maikelnight/zerologonhttps://github.com/McKinnonIT/zabbix-template-CVE-2020-1472https://github.com/metehangelgi/CVE-2020-1472-LABhttps://github.com/midpipps/CVE-2020-1472-Easyhttps://github.com/mingchen-script/CVE-2020-1472-visualizerhttps://github.com/mods20hh/ZeroLogon-PoC-DC-Pwnhttps://github.com/mstxq17/cve-2020-1472https://github.com/murataydemir/CVE-2020-1472https://github.com/NAXG/CVE-2020-1472https://github.com/npocmak/CVE-2020-1472https://github.com/nyambiblaise/Domain-Controller-DC-Exploitation-with-Metasploit-Impackethttps://github.com/PakwanSK/Simulating-and-preventing-Zerologon-CVE-2020-1472-vulnerability-attacks.https://github.com/Privia-Security/ADZerohttps://github.com/puckiestyle/CVE-2020-1472https://github.com/rhymeswithmogul/Set-ZerologonMitigationhttps://github.com/RicYaben/CVE-2020-1472-LABhttps://github.com/risksense/zerologonhttps://github.com/Rvn0xsy/ZeroLogonhttps://github.com/SaharAttackit/CVE-2020-1472https://github.com/SecuraBV/CVE-2020-1472https://github.com/shanfenglan/cve-2020-1472https://github.com/sho-luv/zerologonhttps://github.com/striveben/CVE-2020-1472https://github.com/sv3nbeast/CVE-2020-1472https://github.com/t31m0/CVE-2020-1472https://github.com/tdevworks/CVE-2020-1472-ZeroLogon-Demo-Detection-Mitigationhttps://github.com/thatonesecguy/zerologon-CVE-2020-1472https://github.com/TheJoyOfHacking/dirkjanm-CVE-2020-1472https://github.com/TheJoyOfHacking/SecuraBV-CVE-2020-1472https://github.com/Tobey123/CVE-2020-1472-visualizerhttps://github.com/TuanCui22/ZerologonWithImpacket-CVE2020-1472https://github.com/Udyz/Zerologonhttps://github.com/victim10wq3/CVE-2020-1472https://github.com/VoidSec/CVE-2020-1472https://github.com/Whippet0/CVE-2020-1472https://github.com/whoami-chmod777/Zerologon-Attack-CVE-2020-1472-POChttps://github.com/WiIs0n/Zerologon_CVE-2020-1472https://github.com/wrathfulDiety/zerologonhttps://github.com/YossiSassi/ZeroLogon-Exploitation-Checkhttps://github.com/zeronetworks/zerologon

    Common Weakness Enumeration

    Related CVEs

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High