PT-2020-3668 · Microsoft+10 · Windows Server+11

·

CVE-2020-1472

·

Published

2020-08-11

·

Updated

2026-08-29

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Windows Server versions prior to the fixed version
Description An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run a specially crafted application on a device on the network. To exploit the vulnerability, an unauthenticated attacker would be required to use MS-NRPC to connect to a domain controller to obtain domain administrator access. The vulnerability is related to the ComputeNetlogonCredential function, which uses a fixed initialization vector (IV) in the AES-CFB8 encryption algorithm, allowing an attacker to bypass authentication.
Recommendations To resolve the issue, apply the updates provided by Microsoft as part of their phased two-part rollout, which modify how Netlogon handles the usage of Netlogon secure channels. For guidelines on managing the changes required for this vulnerability, see the Microsoft Technical Security Notifications. As a temporary workaround, consider disabling the ComputeNetlogonCredential function until a patch is available. Restrict access to the vulnerable MS-NRPC protocol to minimize the risk of exploitation. Avoid using the Netlogon protocol until the issue is resolved.
Note: The provided information does not specify the exact fixed version, so it is recommended to update to the latest version available.

Exploit

Fix

LPE

Use of Insufficiently Random Values

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:1647
ALSA-2021_1647
ALT-PU-2020-2839
ALT-PU-2020-2857
AZL-36991
AZL-7350
BDU:2020-04016
CESA-2020_5439
CESA-2021_1647
CVE-2020-1472
DLA-2463-1
ECHO-EF87-C97B-A239
ELSA-2020-5439
ELSA-2021-1647
MGASA-2020-0380
OPENSUSE-SU-2020:1513-1
OPENSUSE-SU-2020:1526-1
OPENSUSE-SU-2020_1513-1
OPENSUSE-SU-2020_1526-1
OPENSUSE-SU-2024:11365-1
OPENSUSE-SU-2024:11370-1
OPENSUSE-SU-2024:11371-1
RHSA-2020:5439
RHSA-2020_5439
RHSA-2021:1647
RHSA-2021:3723
RHSA-2021_1647
RLSA-2021:1647
RLSA-2021_1647
SUSE-FU-2022:4496-1
SUSE-SU-2020:2719-1
SUSE-SU-2020:2720-1
SUSE-SU-2020:2721-1
SUSE-SU-2020:2722-1
SUSE-SU-2020:2724-1
SUSE-SU-2020:2730-1
SUSE-SU-2020_2719-1
SUSE-SU-2020_2720-1
SUSE-SU-2020_2721-1
SUSE-SU-2020_2722-1
SUSE-SU-2020_2724-1
SUSE-SU-2020_2730-1
USN-4510-1
USN-4510-2
USN-4559-1
ZEROLOGONCVE2020_1472

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Windows Server
Red Hat
Rocky Linux
Samba
Suse
Ubuntu
Windows