CVE-2020-1472CISA KEV
Microsoft Netlogon Privilege Escalation Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller. An attacker who successfully exploits the vulnerability could run a specially crafted application on a device on the network. The vulnerability is also known under the moniker of Zerologon.
- Product
- Netlogon
- Added to KEV
- 3 Nov 2021
- Federal remediation due
- 3 May 2022
- Known ransomware use
- Yes