Critical SEVERITY — Vulnerability

Zerologon: Netlogon authentication bypass (CVE-2020-1472)

The legendary CVSS 10.0 vulnerability enabling impersonation of a Domain Controller — enforcement mode active.

Platform
Windows Server
Version
2016
CVE Record
CVE-2020-1472
CVSS Score
10.0/10
Advisory
KB4571694
Published
11 August 2020
Views
4
Primary source: Review the official advisory at msrc.microsoft.com Kaynağa Git

Archive Record

Zerologon (CVE-2020-1472) exploited a cryptographic flaw in the Netlogon remote protocol to allow an attacker to reset the password of a Domain Controller computer account. CVSS: 10.0.

Status

  • As of February 2021, secure RPC is mandatory with enforcement mode enabled
  • On our WS2016 DCs FullSecureChannelProtection is in our internal audit list
  • In new deployments WS2016 no longer assumes the DC role

Windows Server — Related Advisories

VIEW ALL →