ID:9486 - Exploit for Permissions, Privileges, and Access Controls in Windows Server - CVE-2020-1472
Published: January 7, 2024
Windows Server
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to application does not properly impose security restrictions in Netlogon. A remote non-authenticated attacker can use MS-NRPC to connect to a domain controller to obtain domain administrator access. This vulnerability was dubbed ZeroLogon.