Onelogon: How Legacy Netlogon Settings Enable Active Directory Takeover

Researchers have introduced the Onelogon attack as a new way to compromise Active Directory via the Netlogon mechanism. The vulnerability stems from outdated allow-lists that were introduced after Zerologon to maintain compatibility with vulnerable legacy systems. If these exceptions remain in place, an attacker can exploit them to bypass authentication and take over accounts.
What makes this especially critical is that the attack can lead to full domain compromise if domain controller accounts are affected. The paper emphasizes that the root cause lies in configuration and operational practices, not just missing patches or updates.
Products
Active Directory
Netlogon
Onelogon
Zerologon