CVE-2020-1472: Microsoft Netlogon
EPSS99.3%No. 198 of 1739 in KEV
CVE year2020~1 yrs before listing
Same vendor in KEV389
Same product1
| Field | Value |
|---|---|
| Vendor | Microsoft |
| Product | Netlogon |
| Name | Microsoft Netlogon Privilege Escalation Vulnerability |
| Added to KEV | 2021-11-03 |
| US federal due date | 2022-05-03 |
| Ransomware use | Known |
| CWE | CWE-330 |
CISA description
Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller. An attacker who successfully exploits the vulnerability could run a specially crafted application on a device on the network. The vulnerability is also known under the moniker of Zerologon.
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A Microsoft Netlogon vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03.