← Vulnerability feed

Vulnerability record · CVE-2020-1472 · published 17 August 2020

CVE-2020-1472: Microsoft Netlogon elevation of privilege via vulnerable secure channel (Zerologon)

Microsoft · Windows Server 1903

CVE-2020-1472 is an elevation of privilege flaw in Microsoft's Netlogon Remote Protocol (MS-NRPC) where an attacker can establish a vulnerable Netlogon secure channel connection to a domain controller. Microsoft addressed it in a phased two-part rollout modifying how Netlogon handles secure channels. It matters because a successful attack yields domain administrator access.

5.5 CVSS 3.1 Medium CISA KEV since 3 Nov 2021 Known ransomware use EPSS 99% · top 0.1%
5.5CVSS 3.1 base score, v2 9.3
99%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
15Affected product versions listed by NVD
35References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run a specially crafted application on a device on the network. To exploit the vulnerability, an unauthenticated attacker would be required to use MS-NRPC to connect to a domain controller to obtain domain administrator access. Microsoft is addressing the vulnerability in a phased two-part rollout. These updates address the vulnerability by modifying how Netlogon handles the usage of Netlogon secure channels. For guidelines on how to manage the changes required for this vulnerability and more information on the phased rollout, see How to manage the changes in Netlogon secure channel connections associated with CVE-2020-1472 (updated September 28, 2020). When the second phase of Windows updates become available in Q1 2021, customers will be notified via a revision to this security vulnerability. If you wish to be notified when these updates are released, we recommend that you register for the security notifications mailer to be alerted of content changes to this advisory. See Microsoft Technical Security Notifications.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated network exploitation yields domain administrator access, it is in CISA KEV with known ransomware use, and EPSS is near 1.0.

What it is

CVE-2020-1472 is an elevation of privilege flaw in Microsoft's Netlogon Remote Protocol (MS-NRPC) where an attacker can establish a vulnerable Netlogon secure channel connection to a domain controller. Microsoft addressed it in a phased two-part rollout modifying how Netlogon handles secure channels. It matters because a successful attack yields domain administrator access.

Impact

An unauthenticated attacker who exploits the flaw can obtain domain administrator access over the domain controller. This grants full control of the domain, enabling credential theft, persistence and lateral movement.

Attack surface

Reached over the network via MS-NRPC to a domain controller; the description states an unauthenticated attacker is required, so no credentials are needed. No user interaction is described.

Exploitation

CISA KEV lists it as actively exploited with known ransomware campaign use (Black Basta), and EPSS is 0.99389 (99.939th percentile). Public proof-of-concept and exploit references exist.

What to do

  • Apply the Microsoft security updates for CVE-2020-1472 and complete both phases of the Netlogon secure channel rollout.
  • Apply vendor updates for Samba, Fedora, openSUSE, Ubuntu, Debian, Synology and Oracle products listed as affected.
  • Enforce Netlogon secure channel requirements and monitor for the enforcement mode transition per Microsoft guidance.
  • Restrict network access to domain controllers' MS-NRPC/RPC endpoints to trusted management networks only.
  • Rotate domain controller and krbtgt credentials after suspected exploitation.

Detection

  • Monitor Netlogon and domain controller event logs for anomalous secure channel and machine account authentication activity.
  • Alert on unexpected machine account password changes or resets originating from non-domain-controller hosts.
  • Hunt for MS-NRPC traffic to domain controllers from hosts that do not normally perform Netlogon operations.
  • Correlate domain controller authentication events with known Zerologon exploitation patterns and subsequent privileged account use.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-1472 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Microsoft Netlogon Privilege Escalation Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Ransomware crews whose documented playbooks reference this CVE: