Blog | G5 Cyber Security

DHS CISA orders federal agencies to fix Zerologon flaw by Monday

Department of Homeland Securitys CISA issued an emergency directive to order government agencies to address the Zerologon vulnerability (CVE-2020-1472) by Monday. Administrators of enterprise Windows Servers have to install the August 2020 Patch Tuesday to mitigate unacceptable risk posed by the flaw to federal networks. An attacker could exploit the vulnerability to impersonate any computer, including the domain controller itself, and execute remote procedure calls on their behalf. The attack is completely unauthenticated and could be exploited by threat actors to deliver malware and ransomware.”]

Source: https://securityaffairs.co/wordpress/108558/hacking/cisa-emergency-directive-zerologon.html

Exit mobile version