CVE-2020-1472, widely known as ZeroLogon, is a critical elevation of privilege vulnerability within the Netlogon Remote Protocol (MS-NRPC) affecting Microsoft Windows Domain Controllers and Samba implementations. With a maximum CVSS score of 10.0, this flaw permits an unauthenticated attacker with network access to easily establish a vulnerable secure channel and escalate to domain administrator privileges, effectively compromising the entire network. The vulnerability is currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog due to active use in ransomware campaigns, and public exploit modules are readily available in tools such as Metasploit.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_1903:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_1909:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2004:-:*:*:*:*:*:*:* | ||
r2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
samba: Netlogon elevation of privilege vulnerability (Zerologon)
Sep 11, 2020Windows Server Netlogon Remote Protocol Vulnerability (Zerologon)
Aug 17, 2020Netlogon Elevation of Privilege Vulnerability
Aug 11, 2020Windows Server Netlogon Remote Protocol Vulnerability (Zerologon)
Aug 1, 2020A vulnerability in Windows Server allows attackers to use Netlogon Remote Protocol to run a specially-crafted application on a device on the network.