cbcvebase.
CVE-2020-1472
published 2020-08-17

CVE-2020-1472: An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the…

PriorityP1100critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
99.51%
99.9th percentile
An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run a specially crafted application on a device on the network. To exploit the vulnerability, an unauthenticated attacker would be required to use MS-NRPC to connect to a domain controller to obtain domain administrator access. Microsoft is addressing the vulnerability in a phased two-part rollout. These updates address the vulnerability by modifying how Netlogon handles the usage of Netlogon secure channels. For guidelines on how to manage the changes required for this vulnerability and more information on the phased rollout, see How to manage the changes in Netlogon secure channel connections associated with CVE-2020-1472 (updated September 28, 2020). When the second phase of Windows updates become available in Q1 2021, customers will be notified via a revision to this security vulnerability. If you wish to be notified when these updates are released, we recommend that you register for the security notifications mailer to be alerted of content changes to this advisory. See Microsoft Technical Security Notifications.

Affected

56 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiansamba< samba 2:4.13.2+dfsg-2 (bookworm)samba 2:4.13.2+dfsg-2 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
microsoftwindows_server_2008
microsoftwindows_server_2008_r2_service_pack_1>= 6.0.0 < publicationpublication
microsoftwindows_server_2008_r2_service_pack_1>= 6.1.0 < publicationpublication
microsoftwindows_server_2012
microsoftwindows_server_2012>= 6.2.0 < publicationpublication
microsoftwindows_server_2012_r2>= 6.3.0 < publicationpublication
microsoftwindows_server_2016>= 10.0.0 < publicationpublication
microsoftwindows_server_2019>= 10.0.0 < publicationpublication
microsoftwindows_server_version_2004>= 10.0.0 < publicationpublication
microsoftwindows_server_version_20h2>= 10.0.0 < publicationpublication
msrcwindows_server_2008_r2_for_x64-based_systems_service_pack_1
msrcwindows_server_2012
msrcwindows_server_2012_r2
msrcwindows_server_2016
msrcwindows_server_2019
msrcwindows_server_version_1903

Detection & IOCsextracted from sources · hover to see the quote

filenamezero.exe
filenamecheck.exe
filenamecor.bat
domain4a5ikol[.]ru
ip8.211.241.0
  • Detect unauthenticated MS-NRPC connections to domain controllers that attempt to set computer account passwords — core mechanism of Zerologon exploitation.
  • Alert on Netlogon secure channel connections where the initialization vector (IV) is all zeros — this is the cryptographic anomaly that defines Zerologon exploitation.
  • Hunt for Cobalt Strike beacons deployed to domain controllers immediately following Zerologon exploitation — threat actors pivoted to DCs and deployed beacons after obtaining the NTLM hash.
  • Detect rundll32.exe executing a Cobalt Strike DLL with a specific parameter via a batch file (cor.bat) — used for lateral movement post-Zerologon.
  • Detect network connections to 4a5ikol[.]ru (8.211.241.0) — used as Hancitor C2/payload delivery host for Cobalt Strike stagers and Ficker Stealer in this Zerologon intrusion.
  • Ransomware actors exploit CVE-2020-1472 to rapidly escalate to domain administrator — time-to-domain-admin can be under one hour from initial access.
  • ·Microsoft addressed CVE-2020-1472 in a phased two-part rollout; the first patch was released August 2020 and must be applied to all domain controllers. A second enforcement-phase update was planned for Q1 2021.
  • ·CISA issued an emergency directive ordering civilian federal agencies to immediately patch or disable all affected Windows servers; non-governmental organizations were also warned.

CVSS provenance

nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vulncheck5.5MEDIUM
cisa10.0CRITICAL
vendor_msrc10.0CRITICAL
vendor_oracle10.0MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.