Zerologon: Netlogon authentication bypass (CVE-2020-1472)
The legendary CVSS 10.0 vulnerability enabling impersonation of a Domain Controller — enforcement mode active.
The legendary CVSS 10.0 vulnerability enabling impersonation of a Domain Controller — enforcement mode active.
Zerologon (CVE-2020-1472) exploited a cryptographic flaw in the Netlogon remote protocol to allow an attacker to reset the password of a Domain Controller computer account. CVSS: 10.0.
FullSecureChannelProtection is in our internal audit listStack-based buffer overflow in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network.
Integer overflow or wraparound in Windows DHCP Server allows an unauthorized attacker to execute code over a network.
Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally.