Skip to main content

Patch Now: Remediate the Zerologon Vulnerability

  • September 14, 2020
  • 2 replies
  • 66 views

Nic-Automox


Key portion here:


A vulnerability dubbed “Zerologon,” first seen in Microsoft’s August Patch Tuesday security updates, is getting renewed attention due to additional context released by the security organization, Secura. CVE-2020-1472, is a critical CVSS10 vulnerability that allows a malicious threat actor on a corporate network to impersonate the identity of any network computer trying to authenticate against a domain controller, disable related Netlogon security features, and change password credentials on network domain controllers.


TL;DR - if they’re on your corp network, then they can impersonate another machine to the DC and wreak havoc.

How helpful was this post to you?
This topic has been closed for comments

2 replies

Nic-Automox
  • Author
  • Former Automox Employee
  • 832 replies
  • September 17, 2020

There’s now a published exploit, making this even more urgent to patch:


Nic-Automox
  • Author
  • Former Automox Employee
  • 832 replies
  • September 21, 2020


DHS says the update is mandatory for all federal govt agencies and highly recommended for all state and local govt as well.


Cookie policy

We use cookies to enhance and personalize your experience. If you accept you agree to our full cookie policy. Learn more about our cookies.

 
Cookie settings