CVE-2020-1472

MEDIUM KEV RANSOMWARE

Netlogon Weak Cryptographic Authentication

Title source: metasploit

Description

An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run a specially crafted application on a device on the network. To exploit the vulnerability, an unauthenticated attacker would be required to use MS-NRPC to connect to a domain controller to obtain domain administrator access. Microsoft is addressing the vulnerability in a phased two-part rollout. These updates address the vulnerability by modifying how Netlogon handles the usage of Netlogon secure channels. For guidelines on how to manage the changes required for this vulnerability and more information on the phased rollout, see How to manage the changes in Netlogon secure channel connections associated with CVE-2020-1472 (updated September 28, 2020). When the second phase of Windows updates become available in Q1 2021, customers will be notified via a revision to this security vulnerability. If you wish to be notified when these updates are released, we recommend that you register for the security notifications mailer to be alerted of content changes to this advisory. See Microsoft Technical Security Notifications.

Exploits (96)

exploitdb WORKING POC
by West Shepherd · pythonremotewindows
https://www.exploit-db.com/exploits/49071
nomisec WORKING POC 1,804 stars
by bvcyber · poc
https://github.com/bvcyber/CVE-2020-1472
nomisec WORKING POC 1,277 stars
by dirkjanm · remote
https://github.com/dirkjanm/CVE-2020-1472
nomisec WORKING POC 684 stars
by risksense · remote
https://github.com/risksense/zerologon
nomisec WORKING POC 393 stars
by VoidSec · remote
https://github.com/VoidSec/CVE-2020-1472
nomisec WORKING POC 181 stars
by bb00 · remote-auth
https://github.com/bb00/zer0dump
nomisec WORKING POC 112 stars
by mstxq17 · remote
https://github.com/mstxq17/cve-2020-1472
nomisec WORKING POC 84 stars
by Rvn0xsy · remote
https://github.com/Rvn0xsy/ZeroLogon
nomisec WORKING POC 61 stars
by zeronetworks · remote
https://github.com/zeronetworks/zerologon
nomisec WORKING POC 57 stars
by k8gege · remote
https://github.com/k8gege/CVE-2020-1472-EXP
nomisec WORKING POC 38 stars
by cube0x0 · remote
https://github.com/cube0x0/CVE-2020-1472
nomisec WORKING POC 22 stars
by Privia-Security · remote
https://github.com/Privia-Security/ADZero
nomisec WORKING POC 18 stars
by sho-luv · remote
https://github.com/sho-luv/zerologon
nomisec SCANNER 11 stars
by B34MR · poc
https://github.com/B34MR/zeroscan
nomisec SCANNER 11 stars
by WiIs0n · remote
https://github.com/WiIs0n/Zerologon_CVE-2020-1472
nomisec WORKING POC 10 stars
by sv3nbeast · remote
https://github.com/sv3nbeast/CVE-2020-1472
nomisec WORKING POC 8 stars
by thatonesecguy · remote
https://github.com/thatonesecguy/zerologon-CVE-2020-1472
nomisec SCANNER 7 stars
by YossiSassi · poc
https://github.com/YossiSassi/ZeroLogon-Exploitation-Check
github WORKING POC 6 stars
by Y5neKO · pythonpoc
https://github.com/Y5neKO/ExpAndPoc_Collection/tree/main/CVE-2020-1472
nomisec SCANNER 5 stars
by CPO-EH · infoleak
https://github.com/CPO-EH/CVE-2020-1472_ZeroLogonChecker
nomisec WORKING POC 5 stars
by striveben · remote
https://github.com/striveben/CVE-2020-1472
nomisec WORKING POC 3 stars
by guglia001 · remote
https://github.com/guglia001/MassZeroLogon
nomisec WORKING POC 3 stars
by NAXG · remote
https://github.com/NAXG/CVE-2020-1472
nomisec WORKING POC 2 stars
by RicYaben · remote
https://github.com/RicYaben/CVE-2020-1472-LAB
nomisec WORKING POC 2 stars
by whoami-chmod777 · remote
https://github.com/whoami-chmod777/Zerologon-Attack-CVE-2020-1472-POC
nomisec WORKING POC 2 stars
by Akash7350 · remote-auth
https://github.com/Akash7350/CVE-2020-1472
nomisec SCANNER 2 stars
by Anonymous-Family · poc
https://github.com/Anonymous-Family/Zero-day-scanning
nomisec WORKING POC 2 stars
by shanfenglan · remote
https://github.com/shanfenglan/cve-2020-1472
nomisec WORKING POC 2 stars
by rhymeswithmogul · poc
https://github.com/rhymeswithmogul/Set-ZerologonMitigation
nomisec WORKING POC 2 stars
by 0xcccc666 · remote
https://github.com/0xcccc666/cve-2020-1472_Tool-collection
nomisec WORKING POC 2 stars
by CanciuCostin · remote
https://github.com/CanciuCostin/CVE-2020-1472
nomisec WORKING POC 2 stars
by 0xkami · remote
https://github.com/0xkami/CVE-2020-1472
nomisec WORKING POC 1 stars
by mods20hh · remote
https://github.com/mods20hh/ZeroLogon-PoC-DC-Pwn
nomisec WORKING POC 1 stars
by TheJoyOfHacking · remote
https://github.com/TheJoyOfHacking/dirkjanm-CVE-2020-1472
nomisec WORKING POC 1 stars
by Fa1c0n35 · remote
https://github.com/Fa1c0n35/SecuraBV-CVE-2020-1472
nomisec WORKING POC 1 stars
by Udyz · remote
https://github.com/Udyz/Zerologon
nomisec WORKING POC 1 stars
by hell-moon · remote
https://github.com/hell-moon/ZeroLogon-Exploit
nomisec WORKING POC 1 stars
by wrathfulDiety · remote
https://github.com/wrathfulDiety/zerologon
nomisec WORKING POC 1 stars
by b1ack0wl · remote
https://github.com/b1ack0wl/CVE-2020-1472
nomisec SCANNER 1 stars
by mingchen-script · poc
https://github.com/mingchen-script/CVE-2020-1472-visualizer
nomisec WORKING POC 1 stars
by midpipps · remote
https://github.com/midpipps/CVE-2020-1472-Easy
nomisec WRITEUP 1 stars
by murataydemir · poc
https://github.com/murataydemir/CVE-2020-1472
nomisec WORKING POC 1 stars
by npocmak · remote
https://github.com/npocmak/CVE-2020-1472
nomisec WRITEUP 1 stars
by McKinnonIT · poc
https://github.com/McKinnonIT/zabbix-template-CVE-2020-1472
nomisec WORKING POC 1 stars
by jiushill · poc
https://github.com/jiushill/CVE-2020-1472
nomisec WORKING POC
by noemvex · poc
https://github.com/noemvex/apex-predator
gitlab WORKING POC
by NdFeB · poc
https://gitlab.com/NdFeB/zer0dump-installer
gitlab WORKING POC
by darthploit · poc
https://gitlab.com/darthploit/CVE-2020-1472
gitlab WORKING POC
by null-p4n · poc
https://gitlab.com/null-p4n/zerologon
nomisec WORKING POC
by commit2main · remote
https://github.com/commit2main/zerologon-lab
nomisec WRITEUP
by nyambiblaise · poc
https://github.com/nyambiblaise/Domain-Controller-DC-Exploitation-with-Metasploit-Impacket
nomisec WRITEUP
by 100HnoMeuNome · poc
https://github.com/100HnoMeuNome/ZeroLogon-CVE-2020-1472-lab
nomisec WRITEUP
by tdevworks · poc
https://github.com/tdevworks/CVE-2020-1472-ZeroLogon-Demo-Detection-Mitigation
nomisec WRITEUP
by PakwanSK · poc
https://github.com/PakwanSK/Simulating-and-preventing-Zerologon-CVE-2020-1472-vulnerability-attacks.
nomisec WORKING POC
by TuanCui22 · poc
https://github.com/TuanCui22/ZerologonWithImpacket-CVE2020-1472
nomisec WORKING POC
by blackh00d · remote-auth
https://github.com/blackh00d/zerologon-poc
nomisec WRITEUP
by JolynNgSC · poc
https://github.com/JolynNgSC/Zerologon_CVE-2020-1472
nomisec WORKING POC
by metehangelgi · poc
https://github.com/metehangelgi/CVE-2020-1472-LAB
nomisec WORKING POC
by logg-1 · remote
https://github.com/logg-1/0logon
nomisec WORKING POC
by c3rrberu5 · remote
https://github.com/c3rrberu5/ZeroLogon-to-Shell
nomisec WORKING POC
by Anonymous-Family · infoleak
https://github.com/Anonymous-Family/CVE-2020-1472
nomisec WORKING POC
by dr4g0n23 · remote-auth
https://github.com/dr4g0n23/CVE-2020-1472
nomisec WORKING POC
by likeww · remote
https://github.com/likeww/MassZeroLogon
nomisec WORKING POC
by carlos55ml · remote
https://github.com/carlos55ml/zerologon
nomisec WORKING POC
by TheJoyOfHacking · infoleak
https://github.com/TheJoyOfHacking/SecuraBV-CVE-2020-1472
nomisec WORKING POC
by Fa1c0n35 · remote
https://github.com/Fa1c0n35/CVE-2020-1472-02-
nomisec WORKING POC
by puckiestyle · remote
https://github.com/puckiestyle/CVE-2020-1472
nomisec WORKING POC
by itssmikefm · remote
https://github.com/itssmikefm/CVE-2020-1472
nomisec WORKING POC
by SaharAttackit · remote
https://github.com/SaharAttackit/CVE-2020-1472
nomisec WORKING POC
by JayP232 · poc
https://github.com/JayP232/The_big_Zero
nomisec WORKING POC
by Whippet0 · remote
https://github.com/Whippet0/CVE-2020-1472
nomisec SCANNER
by maikelnight · poc
https://github.com/maikelnight/zerologon
nomisec NO CODE
by johnpathe · poc
https://github.com/johnpathe/zerologon-cve-2020-1472-notes
nomisec WORKING POC
by Ken-Abruzzi · remote
https://github.com/Ken-Abruzzi/cve-2020-1472
nomisec SCANNER
by grupooruss · poc
https://github.com/grupooruss/CVE-2020-1472
nomisec WORKING POC
by t31m0 · remote
https://github.com/t31m0/CVE-2020-1472
nomisec WORKING POC
by hectorgie · remote
https://github.com/hectorgie/CVE-2020-1472
nomisec WORKING POC
by victim10wq3 · remote
https://github.com/victim10wq3/CVE-2020-1472
nomisec WORKING POC
by Fa1c0n35 · remote
https://github.com/Fa1c0n35/CVE-2020-1472
nomisec SCANNER
by Tobey123 · poc
https://github.com/Tobey123/CVE-2020-1472-visualizer
metasploit WORKING POC
by Tom Tervoort, Spencer McIntyre, Dirk-jan Mollema · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/dcerpc/cve_2020_1472_zerologon.rb
patchapalooza WORKING POC
by jasminalex · poc
https://gitee.com/jasminalex/CVE-2020-1472
patchapalooza WORKING POC
by trfpatriotic · poc
https://gitee.com/trfpatriotic/CVE-2020-1472
patchapalooza WORKING POC
by mirrors_gladiopeace · poc
https://gitee.com/mirrors_gladiopeace/CVE-2020-1472
patchapalooza WORKING POC
by mirrors_dirkjanm · poc
https://gitee.com/mirrors_dirkjanm/CVE-2020-1472
patchapalooza WORKING POC
by mirrors_SecuraBV · poc
https://gitee.com/mirrors_SecuraBV/CVE-2020-1472
patchapalooza WORKING POC
by keyboxdzd · poc
https://gitee.com/keyboxdzd/zerologon
patchapalooza WORKING POC
by keyboxdzd · poc
https://gitee.com/keyboxdzd/CVE-2020-1472
patchapalooza WORKING POC
by minquangao123 · poc
https://gitee.com/minquangao123/CVE-2020-1472
patchapalooza WORKING POC
by sh3llsas · poc
https://gitee.com/sh3llsas/CVE-2020-1472
patchapalooza WORKING POC
by omg2019 · poc
https://gitee.com/omg2019/CVE-2020-1472
patchapalooza WORKING POC
by csharphpython · poc
https://gitee.com/csharphpython/CVE-2020-1472
patchapalooza WORKING POC
by we88c0de · remote
https://gitlab.com/we88c0de/CVE-2020-1472
patchapalooza WORKING POC
by mos165 · remote
https://github.com/mos165/CVE-20200-1472
patchapalooza WORKING POC
by SecuraBV · remote
https://github.com/SecuraBV/CVE-2020-1472
patchapalooza WRITEUP
by Ascotbe · remote
https://github.com/Ascotbe/Kernelhub

References (18)

Scores

CVSS v3 5.5
EPSS 0.9438
EPSS Percentile 100.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CISA KEV 2021-11-03
VulnCheck KEV 2020-09-24
InTheWild.io 2021-07-23
ENISA EUVD EUVD-2020-12346
Ransomware Use Confirmed
Status published
Products (22)
canonical/ubuntu_linux 14.04
canonical/ubuntu_linux 16.04 (2 CPE variants)
canonical/ubuntu_linux 18.04
canonical/ubuntu_linux 20.04
debian/debian_linux 9.0
fedoraproject/fedora 31
fedoraproject/fedora 32
fedoraproject/fedora 33
microsoft/windows_server_1903
microsoft/windows_server_1909
... and 12 more
Published Aug 17, 2020
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026