Permissions, Privileges, and Access Controls in Windows Server - CVE-2020-1472
Published: August 12, 2020 / Updated: January 7, 2024
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to application does not properly impose security restrictions in Netlogon. A remote non-authenticated attacker can use MS-NRPC to connect to a domain controller to obtain domain administrator access. This vulnerability was dubbed ZeroLogon.
Affected software
Gentoo Linux
Amazon Linux AMI
Arch Linux
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Resilient Storage for x86_64
CentOS
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Red Hat Enterprise Linux for x86_64
Ubuntu
Opensuse
openEuler
Fedora
openchange (Red Hat package)
samba (Alpine package)
samba (Red Hat package)
samba (Ubuntu package)
samba-dc
samba-vfs-glusterfs
samba-dc-bind-dlz
samba-dc-provision
samba-debuginfo
samba-debugsource
samba-devel
samba-help
samba-krb5-printing
samba-libs
samba-test
samba-winbind
samba-winbind-clients
samba-winbind-krb5-locator
samba-winbind-modules
samba-common-tools
samba-common
samba-client
python3-samba-test
python3-samba-dc
python3-samba
libwbclient-devel
libwbclient
libsmbclient-devel
libsmbclient
ctdb-tests
ctdb
samba-pidl
samba
Samba
Huawei FusionAccess
Oracle ZFS Storage Appliance Kit
RoboHelp
Juniper Junos Space
How to mitigate CVE-2020-1472
Samba - addressed in versions 4.10.18, 4.11.13, 4.12.7
samba (Alpine package) - update to 4.12.7-r0
samba (Red Hat package) - addressed in versions 4.10.16-9.el7_9, 4.11.6-112.el7rhgs, 4.13.3-3.el8, 4.13.7-101.el8rhgs
Huawei FusionAccess - update to 6.5.1.SPC004
samba (Ubuntu package) - addressed in versions 2:4.3.11+dfsg-0ubuntu0.14.04.20+esm9, 2:4.3.11+dfsg-0ubuntu0.16.04.30, 2:4.3.11+dfsg-0ubuntu0.16.04.31, 2:4.7.6+dfsg~ubuntu-0ubuntu2.19, 2:4.7.6+dfsg~ubuntu-0ubuntu2.20, 2:4.11.6+dfsg-0ubuntu1.5
samba-dc - update to 4.11.12-2
samba-vfs-glusterfs - update to 4.11.12-2
samba-dc-bind-dlz - update to 4.11.12-2
samba-dc-provision - update to 4.11.12-2
samba-debuginfo - update to 4.11.12-2
samba-debugsource - update to 4.11.12-2
samba-devel - update to 4.11.12-2
samba-help - update to 4.11.12-2
samba-krb5-printing - update to 4.11.12-2
samba-libs - update to 4.11.12-2
samba-test - update to 4.11.12-2
samba-winbind - update to 4.11.12-2
samba-winbind-clients - update to 4.11.12-2
samba-winbind-krb5-locator - update to 4.11.12-2
samba-winbind-modules - update to 4.11.12-2
samba-common-tools - update to 4.11.12-2
samba-common - update to 4.11.12-2
samba-client - update to 4.11.12-2
python3-samba-test - update to 4.11.12-2
python3-samba-dc - update to 4.11.12-2
python3-samba - update to 4.11.12-2
libwbclient-devel - update to 4.11.12-2
libwbclient - update to 4.11.12-2
libsmbclient-devel - update to 4.11.12-2
libsmbclient - update to 4.11.12-2
ctdb-tests - update to 4.11.12-2
ctdb - update to 4.11.12-2
samba-pidl - update to 4.11.12-2
samba - update to 4.11.12-2
samba - addressed in versions 4.11.13-0.fc31, 4.12.7-0.fc32, 4.13.0-0.10.rc6.fc33, 4.13.0-0.10.rc6.fc34, 4.13.0-11.fc33
Juniper Junos Space - update to 21.2R1
Links to Public Exploits and PoC-codes
- Exploit #9486 - 0logon (MS-NRPC (Microsoft NetLogon Remote Protocol)/CVE-2020-1472) (January 7, 2024)
- Exploit #9047 - Zerologon-CVE-2020-1472 (Zerologon exploit for CVE-2020-1472) (May 7, 2023)
- Exploit #9030 - CVE-2020-1472 () (May 2, 2023)
- Exploit #8850 - CVE-2020-1472-LAB (Lab introduction to ZeroLogon) (February 20, 2023)
- Exploit #8623 - CVE-2020-1472 () (November 22, 2022)
- Exploit #8418 - MassZeroLogon (Tool for mass testing ZeroLogon vulnerability CVE-2020-1472) (September 30, 2022)
- Exploit #8390 - CVE-2020-1472 () (September 22, 2022)
- Exploit #8306 - CVE-2020-1473 (Exploit for zerologon cve-2020-1472,And automatically recover the domain control machine hash) (August 28, 2022)
- Exploit #8082 - ad-scanner (Active Directory scanner for MS17-010 MS14-068 CVE-2020-1472 etc...) (June 26, 2022)
- Exploit #8073 - CVE-2020-1472 (ZeroLogon exploitation script,One-click recovery of domain controller machine Hash) (June 23, 2022)
- Exploit #7369 - dirkjanm-CVE-2020-1472 () (February 22, 2022)
- Exploit #6494 - Python_pentest_static_binaries (Static standalone binaries for Windows and Linux (both x64) of dirkjanm's CVE-2020-1472 POC Python scripts) (July 1, 2021)
- Exploit #5645 - ZeroLogon - Netlogon Elevation of Privilege (June 17, 2021)
- Exploit #5311 - CVE-2020-1472 () (April 23, 2021)
- Exploit #5276 - Zerologon (Exploit Code for CVE-2020-1472 aka Zerologon) (April 6, 2021)
- Exploit #5188 - ZeroLogon-Example (Modified the test PoC from Secura, CVE-2020-1472, to change the machine password to null) (March 1, 2021)
- Exploit #5187 - ZeroLogon-Exploit (Modified the test PoC from Secura, CVE-2020-1472, to change the machine password to null) (March 1, 2021)
- Exploit #4983 - zerologon (zerologon script to exploit CVE-2020-1472 CVSS 10/10) (January 3, 2021)
- Exploit #4846 - CVE-2020-1472 () (November 17, 2020)
- Exploit #4824 - CVE-2020-1472 (CVE-2020-1472漏洞复现过程) (November 11, 2020)
- Exploit #4820 - The_big_Zero (The following is the outcome of playing with CVE-2020-1472 and attempting to automate the process of gaining a shell on the DC) (November 10, 2020)
- Exploit #4819 - dirkjanm_CVE-2020-1472_static_binaries (Static standalone binaries for Windows and Linux (both x64) of dirkjanm's CVE-2020-1472 POC Python scripts) (November 10, 2020)
- Exploit #4799 - CVE-2020-1472-visualizer () (November 6, 2020)
- Exploit #4687 - cve-2020-1472 () (October 10, 2020)
- Exploit #4680 - ADZero (Zerologon AutoExploit Tool | CVE-2020-1472) (October 5, 2020)
- Exploit #4669 - Zerologon_CVE-2020-1472 (POC for checking multiple hosts for Zerologon vulnerability) (September 30, 2020)
- Exploit #4660 - CVE-2020-1472-02- () (September 28, 2020)
- Exploit #4659 - CVE-2020-1472 (CVE-2020-1472) (September 28, 2020)
- Exploit #4655 - CVE-2020-1472 (CVE 2020-1472 Script de validación ) (September 25, 2020)
- Exploit #4646 - Netlogon Weak Cryptographic Authentication (September 23, 2020)
- Exploit #4641 - CVE-20200-1472 () (September 21, 2020)
- Exploit #4636 - CVE-2020-1472 ( CVE-2020-1472复现时使用的py文件整理打包) (September 21, 2020)
- Exploit #4632 - CVE-2020-1472 () (September 21, 2020)
- Exploit #4631 - CVE-2020-1472 () (September 21, 2020)
- Exploit #4630 - Zerologon (Zerologon Exploit | CVE-2020-1472) (September 21, 2020)
- Exploit #4629 - CVE-2020-1472-Easy (A simple implementation/code smash of a bunch of other repos) (September 21, 2020)
- Exploit #4628 - zerologon (Test script for CVE-2020-1472 for both RPC/TCP and RPC/SMB) (September 21, 2020)
- Exploit #4623 - cve-2020-1472_Tool-collection (cve-2020-1472_Tool collection) (September 16, 2020)
- Exploit #4622 - CVE-2020-1472 () (September 16, 2020)
- Exploit #4621 - cve-2020-1472 (cve-2020-1472 复现利用及其exp) (September 16, 2020)
- Exploit #4619 - CVE-2020-1472 (https://github.com/dirkjanm/CVE-2020-1472) (September 16, 2020)
- Exploit #4617 - CVE-2020-1472 (CVE-2020-1472漏洞复现过程) (September 16, 2020)
- Exploit #4616 - CVE-2020-1472 () (September 16, 2020)
- Exploit #4615 - CVE-2020-1472 (CVE-2020-1472复现流程) (September 16, 2020)
- Exploit #4614 - CVE-2020-1472 () (September 16, 2020)
- Exploit #4613 - SecuraBV-CVE-2020-1472 () (September 16, 2020)
- Exploit #4612 - CVE-2020-1472 (CVE-2020-1472) (September 16, 2020)
- Exploit #4611 - CVE-2020-1472 (Exploit Code for CVE-2020-1472 aka Zerologon) (September 16, 2020)
- Exploit #4610 - zerologon-CVE-2020-1472 (PoC for Zerologon (CVE-2020-1472) - Exploit) (September 16, 2020)
- Exploit #4609 - zer0dump (Abuse CVE-2020-1472 (Zerologon) to take over a domain and then repair the local stored machine account password.) (September 16, 2020)
- Exploit #4608 - CVE-2020-1472-EXP (Ladon Moudle CVE-2020-1472 Exploit 域控提权神器) (September 16, 2020)
- Exploit #4607 - CVE-2020-1472 (Test tool for CVE-2020-1472) (September 16, 2020)
- Exploit #4606 - CVE-2020-1472 () (September 16, 2020)
- Exploit #4605 - zerologon (Exploit for zerologon cve-2020-1472) (September 16, 2020)
- Exploit #4604 - CVE-2020-1472 (PoC for Zerologon - all research credits go to Tom Tervoort of Secura) (September 16, 2020)
- Exploit #4603 - CVE-2020-1472- (CVE-2020-1472漏洞复现过程) (September 16, 2020)
- Exploit #4551 - CVE-2020-1472-visualizer () (September 1, 2020)
External References
Related Security Bulletins
- Privilege escalation in Microsoft Netlogon
- Unauthenticated domain takeover via netlogon (ZeroLogon) in Samba
- OpenSUSE Linux update for samba
- OpenSUSE Linux update for samba
- Arch Linux update for samba
- Permissions, Privileges, and Access Controls in samba (Alpine package)
- Netlogon elevation of privilege vulnerability in Huawei FusionAccess
- Red Hat Enterprise Linux 7 update for samba
- CentOS 7 update for samba
- Gentoo update for Samba
- Amazon Linux AMI update for samba
- Multiple vulnerabilities in Oracle ZFS Storage Appliance Kit
- Red Hat Enterprise Linux 8 update for samba
- Red Hat Gluster Storage 3.5 on Red Hat Enterprise Linux 8 update for samba
- Multiple vulnerabilities in Junos Space
- Red Hat Gluster Storage Server for On-premise update for samba
- openEuler 20.03 LTS update for samba
- Ubuntu update for samba
- Ubuntu update for samba
- Ubuntu update for samba
- Fedora 34 update for samba
- Fedora 33 update for samba
- Fedora 32 update for samba
- Fedora 31 update for samba
- Fedora 33 update for samba