V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2020-1472
DEB
Critical KEVConfirmedExploit available

An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain con…

CVSS
9.8
Critical
EPSS
0.94
p99
Published
2020-01-01
Updated
2021-11-03
Description

An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run a specially crafted application on a device on the network. To exploit the vulnerability, an unauthenticated attacker would be required to use MS-NRPC to connect to a domain controller to obtain domain administrator access. Microsoft is addressing the vulnerability in a phased two-part rollout. These updates address the vulnerability by modifying how Netlogon handles the usage of Netlogon secure channels. For guidelines on how to manage the changes required for this vulnerability and more information on the phased rollout, see How to manage the changes in Netlogon secure channel connections associated with CVE-2020-1472 (updated September 28, 2020). When the second phase of Windows updates become available in Q1 2021, customers will be notified via a revision to this security vulnerability. If you wish to be notified when these updates are released, we recommend that you register for the security notifications mailer to be alerted of content changes to this advisory. See Microsoft Technical Security Notifications.

Tags · CWE
KEVPre-auth
CWE-287
CAPEC-22
CAPEC-57
CAPEC-94
CAPEC-114
CAPEC-115
CAPEC-151
CAPEC-194
CAPEC-593
CAPEC-633
CAPEC-650
Affected products
Debian_linux
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2020-01-01
Published
2021-11-03
Added to KEV
2021-11-03
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.944 · p99
Known exploited (KEV)
Yes
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-57 · CWE-287
└ via CAPEC-633 · CWE-287
└ via CAPEC-593 · CWE-287
└ via CAPEC-650 · CWE-287
└ via CAPEC-114 · CWE-287
└ via CAPEC-593 · CWE-287
└ via CAPEC-94 · CWE-287
└ via CAPEC-593 · CWE-287
Known exploits — Сканер-ВС
49071
exploitdb · https://www.exploit-db.com/exploits/49071
Enterprise
CVE-2020-1472
github-poc · https://github.com/100HnoMeuNome/ZeroLogon-CVE-2020-1472-lab
Enterprise
Affected software
ProductVendorStatus
openchangeExploited
openchangeExploited
sambaExploited
sambaExploited
sambaExploited
sambaExploited
sambaExploited
sambaExploited
sambaExploited
sambaExploited
sambaExploited
sambaExploited
sambaExploited
debian_linux*Exploited
directory_server*Exploited
fedora*Exploited
leap*Exploited
samba*Exploited
ubuntu_linux*Exploited
windows_server_1903*Exploited
Source databases
DEB
MSR
CVE
RED
UBU
Related vulnerabilities