CVE-2020-1472

Vulnerability updated 23 days ago (2024-11-29T14:00:17.299Z)
Download STIX
Preview STIX
CVE-2020-1472, also known as the "ZeroLogon" vulnerability, is a critical-severity flaw in Microsoft's Netlogon Remote Protocol. This vulnerability, which was patched on August 11, 2020, allows attackers to escalate privileges and gain administrative access to a Windows domain controller without any authentication. The exploitation of this flaw effectively grants threat actors control over a network, posing significant security risks. Throughout 2020, the ZeroLogon vulnerability was widely adopted by threat actors, significantly enhancing both the speed and efficiency of ransomware attacks. In multiple instances, it was used to obtain privileged access to Active Directory and CobaltStrike as the Command and Control (C2) framework. Notably, the RansomHub ransomware incorporated the exploitation of the ZeroLogon vulnerability into its attack chain. In one case, the FBI found a forensic artifact (exp.exe) on a compromised system that likely exploits the Netlogon vulnerability and connects to a domain controller. Threat actors have been observed exploiting the ZeroLogon vulnerability in various ways, including phishing attempts and impersonation of the domain controller. In one such instance, threat actors attempted to impersonate the domain controller by exploiting the ZeroLogon privilege escalation vulnerability. Telemetry data from Vision One also identified the ZeroLogon vulnerability as a potential access vector, further highlighting its widespread use in cyberattacks.
Description last updated: 2024-10-21T08:36:00.913Z
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
Zerologon is a possible alias for CVE-2020-1472. Zerologon (CVE-2020-1472) is a critical vulnerability within Microsoft's Netlogon Remote Protocol that emerged in 2020. It involves a privilege escalation condition that allows an attacker to establish a vulnerable Netlogon secure channel connection to a domain controller, bypassing authentication m
10
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Vulnerability
Exploit
Ransomware
Windows
Phishing
Exploits
exploited
Cuba
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Associated Threat Actors
To see the evidence that has resulted in these threatActor associations, create a free account
Alias DescriptionAssociation TypeVotes
The APT15 Threat Actor is associated with CVE-2020-1472. APT15, also known as Vixen Panda, Nickel, Flea, KE3CHANG, Royal APT, and Playful Dragon, is a threat actor group suspected to be of Chinese origin. The group targets global sectors including trade, economic and financial, energy, and military, aligning with the interests of the Chinese government. IUnspecified
2
The Ransomhub Threat Actor is associated with CVE-2020-1472. RansomHub, a threat actor in the realm of cybersecurity, has emerged as a significant player within the ransomware landscape. The group is known for its malicious activities, including data breaches and extortion attempts. It has been observed that RansomHub affiliates actively participate in campaiUnspecified
2
The Rhysida Threat Actor is associated with CVE-2020-1472. Rhysida is a globally active threat actor known for its ransomware operations, which have impacted a wide range of sectors, particularly the government and public sector. Their use of CleanUpLoader makes their operations highly effective and difficult to detect, as it not only facilitates persistencExploited
2
Source Document References
Information about the CVE-2020-1472 Vulnerability was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
Securelist
24 days ago
CISA
4 months ago
CISA
a month ago
Trend Micro
2 months ago
CISA
2 months ago
Trend Micro
3 months ago
ESET
3 months ago
CISA
4 months ago
InfoSecurity-magazine
5 months ago
DARKReading
7 months ago
CISA
7 months ago
CERT-EU
10 months ago
Securityaffairs
a year ago
CERT-EU
a year ago
CERT-EU
a year ago
Securityaffairs
a year ago
SecurityIntelligence.com
a year ago
CERT-EU
a year ago
Securityaffairs
a year ago
CERT-EU
a year ago