Skip to main content

CVE detail

CVE-2020-1472

An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run a specially crafted application on a device on the network. To exploit the vulnerability, an unauthenticated attacker would be required to use MS-NRPC to connect to a domain controller to obtain domain administrator access. Microsoft is addressing the vulnerability in a phased two-part rollout. These updates address the vulnerability by modifying how Netlogon handles the usage of Netlogon secure channels. For guidelines on how to manage the changes required for this vulnerability and more information on the phased rollout, see How to manage the changes in Netlogon secure channel connections associated with CVE-2020-1472 (updated September 28, 2020). When the second phase of Windows updates become available in Q1 2021, customers will be notified via a revision to this security vulnerability. If you wish to be notified when these updates are released, we recommend that you register for the security notifications mailer to be alerted of content changes to this advisory. See Microsoft Technical Security Notifications.

CVSS 5.5 · MediumBuzz score 81.1KEV listed1 public exploit repository references

Buzz score

Why this CVE is surfacing

Buzz score total 81.1

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 6.1
Mention score
30.0
82 evidence mentions in the snapshot
Diversity score
20.0
8 sources across 3 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
6.1
1 repos · best confidence 0.99
Best PoC traction
3
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
82 source links · newest first
  • NodeZero uncovered and eliminated a Zerologon Active Directory attack path using Iranian tradecraft, validating remediation in under 24 hours.

    exploithorizon3.aiApr 16, 2026, 4:10 PM
  • For years, I watched organizations treat vulnerability data like a compliance chore. It was something to scan, sort and patch against deadlines. Yet buried in those reports is a treasure map of sorts, where an attacker is likely to strike first. In my previous red team and incident responder roles, minus a credential leak or […]

    newswww.csoonline.comNov 19, 2025, 2:06 PM
  • The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) have issued a joint advisory about the activities of a ransomware group from China dubbed Ghost, which has compromised organizations in over 70 countries over the past four years. The Ghost group began its activities in early 2021, but attacks have […]

    newswww.csoonline.comFeb 21, 2025, 8:23 PM
  • Most of the top frequently exploited vulnerabilities in 2023 were initially exploited as zero-days, according to data from government agencies.

    newswww.securityweek.comNov 13, 2024, 3:46 PM
  • Iranian threat actors use brute force techniques in attacks against critical infrastructure organizations, the US, Australia, and Canada warn.

    newswww.securityweek.comOct 17, 2024, 11:33 AM
  • The right tool can make or break a pentest or red team exercise. While many of the tools in Kali are tried and true, they are not always the best fit for every scenario. It is crucial to know where to turn for different needs, ensuring you’re adequately equipped to meet a variety of objectives. […]

    newswww.csoonline.comOct 2, 2024, 10:00 AM
  • The ransomware landscape has seen a lot of fragmentation over the past couple of years with major groups shutting down after they became the target of law enforcement actions or after they attracted too much attention and had ransoms put on their leaders’ identities. Ransomware-as-a-service (RaaS) operations are heavily reliant on third-party hackers, known as […]

    newswww.csoonline.comSep 16, 2024, 7:00 AM
  • Discover the 2024 ransomware landscape: a 4.3% increase in leak site posts compared to the first half of 2023, top targeted sectors and impacted countries.

    vendorunit42.paloaltonetworks.comAug 9, 2024, 10:00 AM
  • One of the most active ransomware groups this year, which operates under the name RansomHub, may have its origins in an older and now defunct ransomware group called Knight, which was itself a rebrand of an older operation known as Cyclops. The links discovered by researchers from Symantec showcase that the ransomware ecosystem is an […]

    newswww.csoonline.comJun 7, 2024, 3:57 PM
  • A ransomware-as-a-service operation known as Black Basta has grown to be one of the most prolific cybercrime threats over the past two years, managing to compromise over 500 organizations from around the world. Many of its victims have been healthcare providers and organizations that operate critical infrastructure, according to the FBI. “Healthcare organizations are attractive […]

    newswww.csoonline.comMay 14, 2024, 9:40 PM
  • Researchers discovered a vulnerability in the code of the Rhysida ransomware that allowed them to develop a decryption tool. Cybersecurity researchers from Kookmin University and the Korea Internet and Security Agency (KISA) discovered an implementation vulnerability in the source code of the Rhysida ransomware. The experts exploited the vulnerability to reconstruct encryption keys and developed […]

    newssecurityaffairs.comFeb 12, 2024, 10:43 PM
  • The Rhysida ransomware group claimed to have hacked Abdali Hospital, a multi-specialty hospital located in Jordan. Abdali Hospital is a multi-specialty hospital located in the modern development of Al-Abdali, Amman, Jordan. Abdali Hospital provides care to patients in numerous specialties. Apart from its general surgery section, it has specialists in orthopedics and rheumatology, gynecology, urology and endocrinology, neurology, nephrology, pulmonology, internal medicine, oncology, […]

    newssecurityaffairs.comDec 26, 2023, 6:03 PM
  • The Rhysida ransomware group claimed to have hacked King Edward VII’s Hospital in London. King Edward VII’s Hospital is a private hospital located on Beaumont Street in the Marylebone district of central London. It is a leading provider of acute and specialist medical care, with a focus on musculoskeletal health, urology, women’s health, and digestive […]

    newssecurityaffairs.comNov 30, 2023, 5:56 AM
  • The Rhysida ransomware group claimed to have hacked the Chinese state-owned energy conglomerate China Energy Engineering Corporation. The Rhysida ransomware gang added the China Energy Engineering Corporation to the list of victims on its Tor leak site. The China Energy Engineering Corporation (CEEC) is a state-owned company in China that operates in the energy and […]

    newssecurityaffairs.comNov 25, 2023, 9:37 PM
  • The Rhysida ransomware group claimed responsibility for the recent cyberattack on the British Library that has caused a major IT outage. The Rhysida ransomware gang added the British Library to the list of victims on its Tor leak site. The British Library is a research library in London that is the national library of the […]

    newssecurityaffairs.comNov 20, 2023, 7:01 PM
  • The FBI and CISA warn of attacks carried out by the Rhysida ransomware group against organizations across multiple industry sectors. FBI and CISA published a joint Cybersecurity Advisory (CSA) to warn of Rhysida ransomware attacks against organizations across multiple industry sectors. The report is part of the ongoing #StopRansomware effort that disseminates advisories about tactics, techniques, and […]

    newssecurityaffairs.comNov 16, 2023, 6:11 AM
  • Old vulnerabilities are still a big problemHelp Net Security

    A recently flagged phishing campaign aimed at delivering the Agent Tesla RAT to unsuspecting users takes advantage of old vulnerabilities in Microsoft Office that allow remote code execution. “Despite fixes for CVE-2017-11882/CVE-2018-0802 being released by Microsoft in November, 2017 and January, 2018, this vulnerability remains popular amongst threat actors, suggesting there are still unpatched devices in the wild, even after over five years,” says Fortinet researcher Xiaopeng Zhang. “We are observing and mitigating 3000 attacks … More →

    newswww.helpnetsecurity.comSep 6, 2023, 1:51 PM
  • Top 12 vulnerabilities routinely exploited in 2022Help Net Security

    Cybersecurity agencies from member countries of the Five Eyes intelligence alliance have released a list of the top 12 vulnerabilities routinely exploited in 2022, plus 30 additional ones also “popular” with attackers. The top 12 “In 2022, malicious cyber actors exploited older software vulnerabilities more frequently than recently disclosed vulnerabilities and targeted unpatched, internet-facing systems. Proof of concept (PoC) code was publicly available for many of the software vulnerabilities or vulnerability chains likely facilitating exploitation … More →

    newswww.helpnetsecurity.comAug 4, 2023, 1:17 PM
  • A Chinese hacking group flagged as APT15 is targeting foreign affairs ministries in the Americas with a new backdoor named Graphican.

    newswww.securityweek.comJun 22, 2023, 2:40 PM
  • CISA, FBI, and ACSC warn critical infrastructure organizations of the BianLian ransomware group’s attacks.

    newswww.securityweek.comMay 17, 2023, 12:47 PM
  • Cuba ransomware gang received more than $60 million in ransom payments related to attacks against 100 entities worldwide as of August 2022. The threat actors behind the Cuba ransomware (aka COLDDRAW, Tropical Scorpius) have demanded over 145 million U.S. Dollars (USD) and received more than $60 million in ransom payments from over 100 victims worldwide […]

    newssecurityaffairs.comDec 2, 2022, 3:20 PM
  • Cuba ransomware attacks on critical infrastructure have continued in 2022, the Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) warn.

    newswww.securityweek.comDec 2, 2022, 12:21 PM
  • The highly active Black Basta ransomware has been linked by cybersecurity firm SentinelOne to the notorious Russian cybercrime group known as FIN7.

    newswww.securityweek.comNov 4, 2022, 12:11 PM
  • Tropical Scorpius has been deploying Cuba Ransomware using novel tools and techniques, such as a new malware family, ROMCOM RAT.

    vendorunit42.paloaltonetworks.comAug 9, 2022, 4:00 PM
  • It’s been more than six months since the Log4Shell vulnerability (CVE-2021-44228) was disclosed, and a number of post-mortems have come out talking about lessons learned and ways to prevent the next Log4Shell-type event from happening.

    exploithorizon3.aiJul 13, 2022, 12:54 PM
  • Conti has been one of the most aggressive ransomware operations over the past two years and continues to victimize many large companies as well as government, law enforcement and healthcare organizations. Researchers warn that unlike other ransomware groups that generally care about their reputation, Conti doesn’t always deliver on its promises to victims. “Usually, the […]

    newswww.csoonline.comMay 31, 2022, 9:00 AM
  • Syxsense has announced a new security and endpoint management solution that delivers vulnerability monitoring and remediation across devices and network environments. The IT management and endpoint security vendor stated that the platform – Syxsense Enterprise – delivers a unified solution that scans and manages all endpoints, resolves problems in real-time, and reduces the risks associated […]

    newswww.csoonline.comMay 3, 2022, 4:01 AM
  • Global cybersecurity authorities have published a joint advisory on the 15 Common Vulnerabilities and Exposures (CVEs) most routinely exploited by malicious cyber actors in 2021. The advisory is co-authored by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), U.S. National Security Agency (NSA), U.S. Federal Bureau of Investigation (FBI), Australian Cyber Security Centre (ACSC), Canadian […]

    newswww.csoonline.comApr 28, 2022, 10:55 AM
  • The 15 most exploited vulnerabilities in 2021Help Net Security

    In 2021, threat actors aggressively exploited newly disclosed critical software vulnerabilities to hit a broad set of targets worldwide, says the latest advisory published by the US Cybersecurity and Infrastructure Security Agency. Most exploited vulnerabilities, new and old Compiled by cybersecurity authorities from the Five Eyes intelligence alliance, the list of top 15 CVEs routinely exploited by attackers in 2021 looks like this: CVE-2021-44228 (aka Log4Shell) – in Apache Log4j CVE-2021-40539 – in Zoho ManageEngine … More →

    newswww.helpnetsecurity.comApr 28, 2022, 7:48 AM
  • Hack The Box – ActiveHorizon3.ai

    NodeZero compromises the “Active” machine on Hack The Box by chaining classic Active Directory vulnerabilities: GPP password exposure, Kerberoasting, and CVE-2020-1472 (ZeroLogon). This advanced walkthrough builds on earlier feedback and demonstrates multiple escalation paths to Domain Admin.

    exploithorizon3.aiSep 5, 2021, 1:45 PM
  • The U.S. government and its allies are pleading with defenders to pay attention to gaping holes in perimeter-type devices, warning that advanced threat actors are feasting on known security defects in VPN appliances, network product gateways and enterprise cloud applications.

    newswww.securityweek.comJul 28, 2021, 3:28 PM
  • Juniper Networks has shipped security patches to cover numerous vulnerabilities across its product portfolio, including a series of critical bugs in third-party software used in the company’s products.

    newswww.securityweek.comJul 19, 2021, 6:20 PM
  • CyberNews researchers analyzed the recently discovered Epsilon Red operations and found that more than 3.5K servers are still vulnerable Several weeks later, security researchers from Sophos have discovered a new ransomware variant known as Epsilon Red. Now, we know exactly how it was carried out – and what you should do to be safe from it. Seemingly, […]

    newssecurityaffairs.comJun 26, 2021, 5:11 AM
  • Oracle this week announced the release of 390 new security fixes as part of the April 2021 Critical Patch Update (CPU), including patches for more than 200 bugs that could be exploited remotely without authentication.

    newswww.securityweek.comApr 21, 2021, 12:02 PM
  • Guardicore unveiled new zero trust assessment capabilities in Infection Monkey, its open source breach and attack simulation tool. Available immediately, security professionals will now be able to conduct zero trust assessments of AWS environments to help identify the potential gaps in an organization’s AWS security posture that can put data at risk. Infection Monkey helps IT security teams assess their organization’s resiliency to unauthorized lateral movement both on-premises and in the cloud. The tool enables … More →

    newswww.helpnetsecurity.comApr 16, 2021, 4:15 AM
  • Network attack trends in the Winter quarter of 2020 revealed some interesting trends, such as increased attacker preference for newly released vulnerabilities and a large uptick in attacks deemed Critical. In addition to details of the newly observed exploits, in this blog, we also dive deep into the exploitation analysis, vendor analysis, attack origin, and attack category distribution.

    vendorunit42.paloaltonetworks.comApr 12, 2021, 5:37 PM
  • FBI and CISA published a joint alert to warn of advanced persistent threat (APT) groups targeting Fortinet FortiOS to access networks of multiple organizations. The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) published a joint alert to warn of attacks carried out by APT groups targeting Fortinet FortiOS servers using multiple exploits. The […]

    newssecurityaffairs.comApr 2, 2021, 9:19 PM
  • On this February 2021 Patch Tuesday: Adobe has fixed a Reader flaw used in limited attacks, as well as delivered security updates for a variety of products, including Acrobat and Reader, Dreamweaver, and Magento Microsoft has plugged 56 security holes, including one actively exploited privilege escalation flaw SAP has released 7 new security notes and updated 6 previously released ones Mozilla has fixed a critical vulnerability affecting Firefox and Firefox ESR on Windows Adobe updates … More →

    newswww.helpnetsecurity.comFeb 9, 2021, 8:09 PM
  • Top 10 most exploited vulnerabilities from 2020Help Net Security

    Vulnerability intelligence-as-a-service outfit vFeed has compiled a list of the top 10 most exploited vulnerabilities from 2020, and among them are SMBGhost, Zerologon, and SIGRed. What is vFeed? vFeed analyzes a variety of vendor advisories and third-party sources, correlates the gathered info, and compiles and constantly updates a vulnerability and threat intelligence database/feed that SOC and security teams can use to prioritize the remediation of security issues. In most cases, securing and protecting companies networks … More →

    newswww.helpnetsecurity.comFeb 3, 2021, 9:51 AM
  • The story of ZeroLogonMalwarebytes Labs

    This is the story of a vulnerability that was brought about by the incorrect use of an encryption technique. After it…

    newswww.malwarebytes.comJan 18, 2021, 5:00 PM
  • Microsoft this week published a reminder for organizations that a February 9 security update will kick off the second phase of patching for the Zerologon vulnerability.

    newswww.securityweek.comJan 15, 2021, 2:57 PM
  • Millions of devices are potential exposed to attacks targeting the vulnerabilities exploited by the tools stolen from the arsenal of FireEye. Security experts from Qualys are warning that more than 7.5 million devices are potentially exposed to cyber attacks targeting the vulnerabilities exploited by the tools stolen from the arsenal of FireEye. As a result […]

    newssecurityaffairs.comDec 24, 2020, 7:15 PM
  • Palo Alto Networks commends FireEye for transparency around its reported breach and is working to use the information shared to protect our customers.

    vendorunit42.paloaltonetworks.comDec 11, 2020, 5:10 AM
  • The UK NCSC issued an alert to urge organizations to patch the critical CVE-2020-15505 RCE vulnerability in MobileIron MDM systems. The UK National Cyber Security Centre (NCSC) issued an alert urging organizations to address the critical CVE-2020-15505 remote code execution (RCE) vulnerability in MobileIron mobile device management (MDM) systems. MDM platforms allow administrators to remotely manage a fleet of […]

    newssecurityaffairs.comNov 25, 2020, 9:13 AM
  • A threat actor has published online a list of one-line exploits to steal VPN credentials from over 49,000 vulnerable Fortinet VPNs. A threat actor, who goes online with the moniker “pumpedkicks,” has leaked online a list of exploits that could be exploited to steal VPN credentials from almost 50,000 Fortinet VPN devices. Researchers from Bank Security first […]

    newssecurityaffairs.comNov 22, 2020, 6:07 PM
  • Ransomware is once again in the news. Attackers are reportedly targeting health care providers and are using targeted phishing campaigns disguised as meeting invites or invoices that contain links to Google documents, which then lead to PDFs with links to signed executables that have names with distinctive words like “preview” and “test”. Once the ransomware […]

    newswww.csoonline.comNov 18, 2020, 11:00 AM
  • Microsoft this week revealed that it continues to receive reports from customers of attacks targeting the Zerologon vulnerability.

    newswww.securityweek.comOct 30, 2020, 2:30 PM
  • Microsoft researchers are warning that threat actors are continuing to actively exploit the ZeroLogon vulnerability in attacks in the wild. Microsoft is warning that threat actors are actively exploiting the ZeroLogon vulnerability in the Netlogon Remote Protocol. The CVE-2020-1472 flaw is an elevation of privilege that resides in the Netlogon. The Netlogon service is an Authentication Mechanism used in the Windows Client […]

    newssecurityaffairs.comOct 30, 2020, 8:25 AM
  • The US government declared that Russia-linked APT group Energetic Bear has breached US government networks and exfiltrated data. A joint security advisory published by The Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) revealed that Russia-linked APT group Energetic Bear has breached US government networks and exfiltrated data. The Energetic Bear […]

    newssecurityaffairs.comOct 23, 2020, 11:10 AM
  • The United States says Russian state-sponsored hacking group Energetic Bear has successfully compromised state, local, territorial, and tribal (SLTT) government networks and stole data from at least two servers.

    newswww.securityweek.comOct 23, 2020, 10:35 AM
  • Taiwanese vendor QNAP published an advisory to warn customers that certain versions of its NAS OS (QTS) are affected by the Zerologon vulnerability. The Taiwanese vendor QNAP has published an advisory to warn customers that certain versions of the operating system for its network-attached storage (NAS) devices, also known as of QTS, are affected by […]

    newssecurityaffairs.comOct 22, 2020, 1:10 PM
  • The U.S. National Security Agency this week released an advisory containing information on 25 vulnerabilities that are being actively exploited or targeted by Chinese state-sponsored threat actors.

    newswww.securityweek.comOct 21, 2020, 11:06 AM
  • The US Cybersecurity and Infrastructure Security Agency (CISA) has released a list of 25 vulnerabilities Chinese state-sponsored hackers have been recently scanning for or have exploited in attacks. “Most of the vulnerabilities […] can be exploited to gain initial access to victim networks using products that are directly accessible from the Internet and act as gateways to internal networks. The majority of the products are either for remote access or for external web services, and … More →

    newswww.helpnetsecurity.comOct 21, 2020, 10:23 AM
  • The US National Security Agency (NSA) has shared the list of top 25 vulnerabilities exploited by Chinese state-sponsored hacking groups in attacks in the wild. The US National Security Agency (NSA) has published a report that includes details of the top 25 vulnerabilities that are currently being exploited by China-linked APT groups in attacks in the […]

    newssecurityaffairs.comOct 20, 2020, 7:28 PM
  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that government networks have been targeted in attacks exploiting the Zerologon vulnerability in combination with flaws affecting Fortinet and MobileIron products.

    newswww.securityweek.comOct 12, 2020, 12:56 PM
  • US government networks are under attack, threat actors chained VPN and Windows Zerologon flaws to gain unauthorized access to elections support systems. The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) published a joint security alert to warn of attackers combining VPN and Windows Zerologon flaws to target government networks. […]

    newssecurityaffairs.comOct 12, 2020, 11:29 AM
  • Microsoft has uncovered Zerologon attacks that were allegedly conducted by the infamous TA505 Russia-linked cybercrime group. Microsoft spotted a series of Zerologon attacks allegedly launched by the Russian cybercrime group tracked as TA505, CHIMBORAZO and Evil Corp. Microsoft experts spotted the Zerologon attacks involving fake software updates, the researchers noticed that the malicious code connected […]

    newssecurityaffairs.comOct 10, 2020, 5:42 PM
  • Microsoft reported this week that it has spotted Zerologon attacks apparently conducted by TA505, a notorious Russia-linked cybercrime group.

    newswww.securityweek.comOct 9, 2020, 3:12 PM
  • It’s October and that means Halloween will be here at the end of the month. It won’t be much fun if we only get to ‘dress up’ and look at each other via video conference. But then, we’ve had a lot of ‘tricks’ thrown at us this last month – Zerologon, explosion of ransomware, COVID phishing attacks, and more. Will we get more tricks next week or are we in for a treat on Patch … More →

    newswww.helpnetsecurity.comOct 9, 2020, 6:16 AM
  • Using a WordPress flaw (File-Manager plugin–CVE-2020-25213) to leverage Zerologon (CVE-2020-1472) and attack companies’ Domain Controllers. Recently, a critical vulnerability called Zerologon – CVE-2020-1472 – has become a trending subject around the globe. This vulnerability would allow a malicious agent with a foothold on your internal network to essentially become Domain Admin with just one click. This scenario […]

    newssecurityaffairs.comOct 7, 2020, 6:03 AM
  • The Iran-linked threat actor known as MuddyWater is actively targeting the Zerologon vulnerability in Windows Server, Microsoft warns.

    newswww.securityweek.comOct 6, 2020, 8:22 AM
  • Microsoft researchers reported that Iranian cyber espionage group MuddyWater is exploiting the Zerologon vulnerability in attacks in the wild. Microsoft published a post and a series of tweets to warn of cyber attacks exploiting the Zerologon vulnerability carried out by the Iran-linked APT group known as MuddyWater, aka Mercury. The Zerologon vulnerability, tracked as CVE-2020-1472, is […]

    newssecurityaffairs.comOct 6, 2020, 7:41 AM
  • Microsoft has published a support article to provide guidance on what organizations need to do to ensure that they are not exposed to attacks targeting the Zerologon vulnerability.

    newswww.securityweek.comOct 1, 2020, 8:47 AM
  • 29th September – Threat Intelligence BulletinCheck Point Research

    For the latest discoveries in cyber research for the week of 29th September 2020, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Following last week’s emergency directive issued by CISA, Microsoft has warned that attackers are actively exploiting the critical Zerologon vulnerability (CVE-2020-1472) to attack Microsoft Windows servers using publicly available PoC exploits. […]

    vendorresearch.checkpoint.comSep 29, 2020, 9:58 AM
  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert to warn of attackers actively targeting a recently addressed vulnerability in the Microsoft Windows Netlogon Remote Protocol (MS-NRPC).

    newswww.securityweek.comSep 28, 2020, 2:03 PM
  • Security Affairs newsletter Round 283Security Affairs

    A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs free for you in your email box. IPG Photonics high-performance laser developer hit with ransomware Mozi Botnet is responsible for most of the IoT Traffic Alleged Activision hack, 500,000 Call Of Duty players impacted DHS CISA orders […]

    newssecurityaffairs.comSep 27, 2020, 10:37 AM
  • Here’s an overview of some of last week’s most interesting news and articles: CISA orders federal agencies to implement Zerologon fix If you had any doubts about the criticality of the Zerologon vulnerability (CVE-2020-1472) affecting Windows Server, here is a confirmation: the US Cybersecurity and Infrastructure Security Agency (CISA) has issued an emergency directive instructing federal agencies to “immediately apply the Windows Server August 2020 security update to all domain controllers.” What are the traits … More →

    newswww.helpnetsecurity.comSep 27, 2020, 7:55 AM
  • Microsoft says it has observed threat actors actively targeting the Zerologon vulnerability affecting Windows Server.

    newswww.securityweek.comSep 24, 2020, 12:38 PM
  • Microsoft recently released a patch (CVE-2020-1472) to fix a software issue in the Microsoft Windows Netlogon Remote Protocol (MS-NRPC). As noted on a Secura blog, an unauthenticated attacker with network access to a domain controller could exploit this vulnerability, dubbed Zerologon, to compromise all Active Directory (AD) identity services. An attacker does not need credentials […]

    newswww.csoonline.comSep 24, 2020, 10:00 AM
  • Microsoft is warning of threat actors that are actively using the Windows Server Zerologon exploits in attacks in the wild. Microsoft has published a series of Tweets to warn of attackers that are actively exploiting the Windows Server Zerologon in attacks in the wild. The IT giant is urging Windows administrators to install the released […]

    newssecurityaffairs.comSep 24, 2020, 8:42 AM
  • Samba team has released a security patch to address the Zerologon issue in the Microsoft Windows Netlogon Remote Protocol (MS-NRPC). Samba team has released a security patch to address the Zerologon (CVE-2020-1472) issue in the Microsoft Windows Netlogon Remote Protocol (MS-NRPC). The CVE-2020-1472 flaw is an elevation of privilege that resides in the Netlogon. The Netlogon service is an Authentication […]

    newssecurityaffairs.comSep 23, 2020, 2:34 PM
  • The Samba team has released patches for a critical-severity elevation of privilege vulnerability impacting the Microsoft Windows Netlogon Remote Protocol (MS-NRPC).

    newswww.securityweek.comSep 23, 2020, 11:47 AM
  • On Friday, September 18, the US Cybersecurity and Infrastructure Security Agency (CISA) ordered all federal agencies to patch a critical privilege escalation flaw that affects Windows servers and could allow hackers to take over Windows networks. A patch has existed for the vulnerability — dubbed Zerologon — since August, but recently released technical details allowed […]

    newswww.csoonline.comSep 23, 2020, 10:00 AM
  • 21st September – Threat Intelligence BulletinCheck Point Research

    For the latest discoveries in cyber research for the week of 21st September 2020, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Check Point Research has unraveled an ongoing surveillance operation by Iranian entities that have been targeting Iranian expats and dissidents for years. The campaign targets both PCs and mobile devices, and […]

    vendorresearch.checkpoint.comSep 21, 2020, 1:35 PM
  • If you had any doubts about the criticality of the Zerologon vulnerability (CVE-2020-1472) affecting Windows Server, here is a confirmation: the US Cybersecurity and Infrastructure Security Agency (CISA) has issued on Friday an emergency directive instructing federal agencies to “immediately apply the Windows Server August 2020 security update to all domain controllers” – and to do so by the end of Monday (September 21). “If affected domain controllers cannot be updated, ensure they are removed … More →

    newswww.helpnetsecurity.comSep 21, 2020, 12:19 PM
  • The Department of Homeland Security (DHS) on Friday issued an Emergency Directive that requires federal agencies to install fixes for a Netlogon elevation of privilege vulnerability for which Microsoft released patches in August 2020.

    newswww.securityweek.comSep 21, 2020, 8:44 AM
  • DHS CISA issued an emergency directive to tells government agencies to address the Zerologon vulnerability (CVE-2020-1472) by Monday. The Department of Homeland Security’s CISA issued an emergency directive to order government agencies to address the Zerologon vulnerability (CVE-2020-1472) by Monday. The CVE-2020-1472 flaw is an elevation of privilege that resides in the Netlogon. The Netlogon service is an Authentication Mechanism […]

    newssecurityaffairs.comSep 21, 2020, 6:58 AM
  • Here’s an overview of some of last week’s most interesting news, reviews and articles: Most people ignore QR code security concerns QR codes are rising in popularity and use, according to a consumer sentiment study by MobileIron. Sixty-four percent of respondents stated that a QR code makes life easier in a touchless world – despite a majority of people lacking security on their mobile devices, with 51% of respondents stating they do not have or … More →

    newswww.helpnetsecurity.comSep 20, 2020, 7:55 AM
  • CVE-2020-1472, also known as "Zerologon," was given a "critical" security rating from Microsoft and a CVSS score of 10.0.

    vendorunit42.paloaltonetworks.comSep 17, 2020, 9:00 PM
  • CVE-2020-1472, a privilege elevation vulnerability in the Netlogon Remote Protocol (MS-NRPC) for which Microsoft released a patch in August, has just become a huge liability for organizations that are struggling with timely patching. Secura researchers – the very same ones who found and disclosed the flaw to Microsoft – have published additional technical details on Monday, and just a few hours later several PoC exploit/tools have been published on GitHub. About CVE-2020-1472 CVE-2020-1472 (aka Zerologon) … More →

    newswww.helpnetsecurity.comSep 15, 2020, 9:58 AM
  • Zerologon attack allows threat actors to take over enterprise networks by exploiting the CVE-2020-1472 patched in the August 2020 Patch Tuesday. Administrators of enterprise Windows Servers have to install the August 2020 Patch Tuesday as soon as possible to protect their systems from Zerologon attack that exploits the CVE-2020-1472. The CVE-2020-1472 flaw is an elevation of privilege […]

    newssecurityaffairs.comSep 14, 2020, 11:48 AM
  • On this August 2020 Patch Tuesday: Microsoft has plugged 120 flaws, two of which are being exploited in attacks in the wild Adobe has delivered security updates for Adobe Acrobat, Reader and Lightroom Apple has released updates for iCloud on Windows Google has updated Chrome with security fixes Microsoft’s updates Microsoft has released patched for 120 CVEs, 17 of which are critical and the rest important. One (CVE-2020-1464) is publicly known and being actively exploited, … More →

    newswww.helpnetsecurity.comAug 11, 2020, 6:37 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

1 repository references · best confidence 0.99 · max 3 stars

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence