CVE-2020-1472

CVSS 3.1 Score 10.0 of 10 (high)

Details

Published Aug 17, 2020
Updated: May 23, 2024
CWE ID 330

Summary

CVE-2020-1472 is an elevation of privilege vulnerability that allows unauthenticated attackers to establish a vulnerable Netlogon secure channel connection to a domain controller using the Netlogon Remote Protocol (MS-NRPC). If successfully exploited, an attacker could gain domain administrator access and run a specially crafted application on a networked device. Microsoft is addressing this vulnerability through a phased two-part rollout, with the first phase modifying how Netlogon handles secure channels. The second phase of updates is scheduled for Q1 2021. To manage the changes required for this vulnerability, consult Microsoft's guidelines on managing Netlogon secure channel connections associated with CVE-2020-1472. For updates on the phased rollout and release of the second phase of updates, register for Microsoft's security notifications mailer.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share