CVE-2020-1472: Zerologon
A cryptographic flaw in the Netlogon Remote Protocol (MS-NRPC) that Windows domain controllers use to authenticate machine accounts. A weak AES-CFB8 initialization vector implementation lets an attacker with network access to a domain controller reset its computer account password and impersonate it, gaining full control of the Active Directory domain with zero credentials required.
View the authoritative record on NVD ↗Affected software
- Windows Server domain controllers (2008 through 2019, prior to the August 2020 update)
How it's exploited
Send a burst of Netlogon authentication requests with an all-zero client challenge; because of the flawed IV handling, roughly 1 in 256 attempts succeeds in authenticating with an all-zero session key, letting the attacker reset the domain controller's machine account password.
Severity
CVE-2020-1472 carries a CVSS 3.1 base score of 10.0, rated Critical. See how CVSS scoring works or score a vulnerability yourself with the free CVSS calculator.
Weakness type
CVE-2020-1472 is categorized under CWE-330, the general weakness pattern behind this specific vulnerability.
How TurboPentest tests for this (white-box)
This weakness (Use of Insufficiently Random Values) is caught by white-box static analysis when you connect a GitHub repo: IntegSec's Opengrep SAST rule pack carries 5 rules for it, flagging the issue directly in your source code as part of the pentest.
Remediation
Apply Microsoft's August 2020 security update, then complete the follow-up enforcement phase so the domain controller rejects vulnerable, unpatched connection attempts outright.
Frequently asked questions
What is CVE-2020-1472?
A cryptographic flaw in the Netlogon Remote Protocol (MS-NRPC) that Windows domain controllers use to authenticate machine accounts. A weak AES-CFB8 initialization vector implementation lets an attacker with network access to a domain controller reset its computer account password and impersonate it, gaining full control of the Active Directory domain with zero credentials required.
How severe is CVE-2020-1472?
CVE-2020-1472 has a CVSS 3.1 base score of 10.0 out of 10, rated Critical.
What software is affected by CVE-2020-1472?
CVE-2020-1472 affects Windows Server domain controllers (2008 through 2019, prior to the August 2020 update).
How do you fix CVE-2020-1472?
Apply Microsoft's August 2020 security update, then complete the follow-up enforcement phase so the domain controller rejects vulnerable, unpatched connection attempts outright.
Where is the authoritative record for CVE-2020-1472?
The National Vulnerability Database (NVD) publishes the authoritative record for CVE-2020-1472 at https://nvd.nist.gov/vuln/detail/CVE-2020-1472, including the current CVSS score, CWE mapping, and affected-configuration data.
Related CVEs
About this reference
These security references are maintained by IntegSec, an offensive-security firm whose team holds CISSP, OSCP, and OSCE certifications and has run thousands of penetration tests. Content is kept current as tools, standards, and attack techniques evolve.
Find known-vulnerable services before an attacker does
TurboPentest fingerprints every open port and web service, then matches detected versions against known CVEs automatically, from $99 per target.
Start a pentest