PT-2020-3668 · Microsoft+10 · Windows Server+11
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows Server versions prior to the fixed version
Description
An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run a specially crafted application on a device on the network. To exploit the vulnerability, an unauthenticated attacker would be required to use MS-NRPC to connect to a domain controller to obtain domain administrator access. The vulnerability is related to the
ComputeNetlogonCredential function, which uses a fixed initialization vector (IV) in the AES-CFB8 encryption algorithm, allowing an attacker to bypass authentication.Recommendations
To resolve the issue, apply the updates provided by Microsoft as part of their phased two-part rollout, which modify how Netlogon handles the usage of Netlogon secure channels. For guidelines on managing the changes required for this vulnerability, see the Microsoft Technical Security Notifications. As a temporary workaround, consider disabling the
ComputeNetlogonCredential function until a patch is available. Restrict access to the vulnerable MS-NRPC protocol to minimize the risk of exploitation. Avoid using the Netlogon protocol until the issue is resolved.Note: The provided information does not specify the exact fixed version, so it is recommended to update to the latest version available.
Exploit
Fix
LPE
Use of Insufficiently Random Values
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Windows Server
Red Hat
Rocky Linux
Samba
Suse
Ubuntu
Windows