{"cveID":"CVE-2020-1472","vendorProject":"Microsoft","product":"Netlogon","vulnerabilityName":"Microsoft Netlogon Privilege Escalation Vulnerability","dateAdded":"2021-11-03","shortDescription":"Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller. An attacker who successfully exploits the vulnerability could run a specially crafted application on a device on the network. The vulnerability is also known under the moniker of Zerologon.","requiredAction":"Apply updates per vendor instructions.","dueDate":"2022-05-03","knownRansomwareCampaignUse":"Known","notes":"Reference CISA's ED 20-04 (https://www.cisa.gov/news-events/directives/ed-20-04-mitigate-netlogon-elevation-privilege-vulnerability-august-2020-patch-tuesday) for further guidance and requirements. Note: The due date for addressing this vulnerability aligns with the requirements outlined in ED 20-04. https://nvd.nist.gov/vuln/detail/CVE-2020-1472","cwes":["CWE-330"],"year":2020,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2020-1472","technique":"T1110","technique_name_at_mapping":"Brute Force","mapping_type":"exploitation_technique","capability_group":"priv_escalation","comments":"CVE-2020-1472 is a privilege elevation vulnerability. The immediate effect of successful exploitation results in the ability to authentication to the vulnerable Domain Controller with Domain Administrator level credentials. In compromises exploiting this vulnerability, exploitation was typically followed immediately by dumping all hashes for Domain accounts.","references":["https://www.crowdstrike.com/en-us/blog/cve-2020-1472-zerologon-security-advisory/","https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-209a"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2020-1472","technique":"T1133","technique_name_at_mapping":"External Remote Services","mapping_type":"exploitation_technique","capability_group":"priv_escalation","comments":"CVE-2020-1472, an elevation of privilege vulnerability in Microsoft’s Netlogon. A remote attacker can exploit this vulnerability to breach unpatched Active Directory domain controllers and obtain domain administrator access. ","references":["https://www.bleepingcomputer.com/news/security/fbi-and-cisa-warn-of-opportunistic-rhysida-ransomware-attacks/","https://therecord.media/cisa-cuba-ransomware-group-has-stolen-60-million-from-at-least-100-organizations","https://msrc.microsoft.com/blog/2020/10/attacks-exploiting-netlogon-vulnerability-cve-2020-1472/","https://www.cisa.gov/news-events/alerts/2020/09/24/unpatched-domain-controllers-remain-vulnerable-netlogon-vulnerability#:~:text=The%20Cybersecurity%20and%20Infrastructure%20Security","and%20obtain%20domain%20administrator%20access."],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2020-1472","technique":"T1021","technique_name_at_mapping":"Remote Services","mapping_type":"primary_impact","capability_group":"priv_escalation","comments":"CVE-2020-1472 is a privilege elevation vulnerability. The immediate effect of successful exploitation results in the ability to authentication to the vulnerable Domain Controller with Domain Administrator level credentials. In compromises exploiting this vulnerability, exploitation was typically followed immediately by dumping all hashes for Domain accounts.","references":["https://www.crowdstrike.com/en-us/blog/cve-2020-1472-zerologon-security-advisory/","https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-209a"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2020-1472","technique":"T1068","technique_name_at_mapping":"Exploitation for Privilege Escalation","mapping_type":"primary_impact","capability_group":"priv_escalation","comments":"CVE-2020-1472, an elevation of privilege vulnerability in Microsoft’s Netlogon. A remote attacker can exploit this vulnerability to breach unpatched Active Directory domain controllers and obtain domain administrator access. ","references":["https://www.bleepingcomputer.com/news/security/fbi-and-cisa-warn-of-opportunistic-rhysida-ransomware-attacks/","https://therecord.media/cisa-cuba-ransomware-group-has-stolen-60-million-from-at-least-100-organizations","https://www.cisa.gov/news-events/alerts/2020/09/24/unpatched-domain-controllers-remain-vulnerable-netlogon-vulnerability#:~:text=The%20Cybersecurity%20and%20Infrastructure%20Security","and%20obtain%20domain%20administrator%20access."],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2020-1472","technique":"T1087.002","technique_name_at_mapping":"Domain Account","mapping_type":"secondary_impact","capability_group":"priv_escalation","comments":"CVE-2020-1472 is a privilege elevation vulnerability. The immediate effect of successful exploitation results in the ability to authentication to the vulnerable Domain Controller with Domain Administrator level credentials. In compromises exploiting this vulnerability, exploitation was typically followed immediately by dumping all hashes for Domain accounts.","references":["https://www.crowdstrike.com/en-us/blog/cve-2020-1472-zerologon-security-advisory/","https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-209a"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2020-1472","technique":"T1087.002","technique_name_at_mapping":"Domain Account","mapping_type":"primary_impact","capability_group":"priv_escalation","comments":"CVE-2020-1472, an elevation of privilege vulnerability in Microsoft’s Netlogon. A remote attacker can exploit this vulnerability to breach unpatched Active Directory domain controllers and obtain domain administrator access. ","references":["https://www.bleepingcomputer.com/news/security/fbi-and-cisa-warn-of-opportunistic-rhysida-ransomware-attacks/","https://therecord.media/cisa-cuba-ransomware-group-has-stolen-60-million-from-at-least-100-organizations","https://www.cisa.gov/news-events/alerts/2020/09/24/unpatched-domain-controllers-remain-vulnerable-netlogon-vulnerability#:~:text=The%20Cybersecurity%20and%20Infrastructure%20Security","and%20obtain%20domain%20administrator%20access."],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2020-1472","technique":"T1133","technique_name_at_mapping":"External Remote Services","mapping_type":"secondary_impact","capability_group":"priv_escalation","comments":"CVE-2020-1472 is a privilege escalation vulnerability in Windows Netlogon. After gaining initial access, the actors exploit CVE-2020-1472 to compromise all Active Directory (AD) identity services. Actors have then been observed using legitimate remote access tools, such as VPN and Remote Desktop Protocol (RDP), to access the environment with the compromised credentials.","references":["https://cisa.gov/news-events/cybersecurity-advisories/aa20-283a"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2020-1472","technique":"T1486","technique_name_at_mapping":"Data Encrypted for Impact","mapping_type":"secondary_impact","capability_group":"priv_escalation","comments":"CVE-2020-1472, an elevation of privilege vulnerability in Microsoft’s Netlogon. A remote attacker can exploit this vulnerability to breach unpatched Active Directory domain controllers and obtain domain administrator access. CVE-2020-1472 has been reported to be exploited by Ransomware groups for initial access.  ","references":["https://www.bleepingcomputer.com/news/security/fbi-and-cisa-warn-of-opportunistic-rhysida-ransomware-attacks/","https://therecord.media/cisa-cuba-ransomware-group-has-stolen-60-million-from-at-least-100-organizations","https://www.cisa.gov/news-events/alerts/2020/09/24/unpatched-domain-controllers-remain-vulnerable-netlogon-vulnerability#:~:text=The%20Cybersecurity%20and%20Infrastructure%20Security","and%20obtain%20domain%20administrator%20access."],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1021","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Remote Services","name_at_mapping":"Remote Services","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":11,"has_detection_strategy":true},{"id":"T1068","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Exploitation for Privilege Escalation","name_at_mapping":"Exploitation for Privilege Escalation","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":31,"has_detection_strategy":true},{"id":"T1087.002","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Domain Account","name_at_mapping":"Domain Account","renamed":false,"revoked_by":null,"mapping_types":["primary_impact","secondary_impact"],"sigma_rule_count":21,"has_detection_strategy":true},{"id":"T1110","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Brute Force","name_at_mapping":"Brute Force","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":25,"has_detection_strategy":true},{"id":"T1133","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"External Remote Services","name_at_mapping":"External Remote Services","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique","secondary_impact"],"sigma_rule_count":20,"has_detection_strategy":true},{"id":"T1486","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Data Encrypted for Impact","name_at_mapping":"Data Encrypted for Impact","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":16,"has_detection_strategy":true}],"mapping_types":["exploitation_technique","primary_impact","secondary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"full","sigma_rules_tagged_cve":["dcc6a01e-9471-44a0-a699-71ea96f8ed8b","dd7876d8-0f09-11eb-adc1-0242ac120002"],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-24 19:45 UTC","_attack_version":"19.2"}