Blog | G5 Cyber Security

Microsoft’s Zerologon vulnerability fix: What admins need to know

Microsoft recently released a patch (CVE-2020-1472) to fix a software issue in the Microsoft Windows Netlogon Remote Protocol (MS-NRPC) An unauthenticated attacker with network access to a domain controller could exploit this vulnerability. An attacker does not need credentials to gain privileges on the network, only access to the domain. The US Cybersecurity and Infrastructure Security Agency (CISA) warns that exploit code for this vulnerability has been released to the web, and Microsoft reports that it has already observed attacks where those public exploits have been used.”]

Source: https://www.csoonline.com/article/3576289/what-admins-need-to-know-about-microsofts-zerologon-vulnerability-fix.html

Exit mobile version