CVE-2020-1472General(canonical / debian_linux)

MEDIUMCVSS 10.0 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch canonical debian_linux systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run a specially crafted application on a device on the network. To exploit the vulnerability, an unauthenticated attacker would be required to use MS-NRPC to connect to a domain controller to obtain domain administrator access. Microsoft is addressing the vulnerability in a phased two-part rollout. These updates address the vulnerability by modifying how Netlogon handles the usage of Netlogon secure channels. For guidelines on how to manage the changes required for this vulnerability and more information on the phased rollout, see How to manage the changes in Netlogon secure channel connections associated with CVE-2020-1472 (updated September 28, 2020). When the second phase of Windows updates become available in Q1 2021, customers will be notified via a revision to this security vulnerability. If you wish to be notified when these updates are released, we recommend that you register for the security notifications mailer to be alerted of content changes to this advisory. See Microsoft Technical Security Notifications.

5.3/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-05-03. Apply updates per vendor instructions.

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • debian_linux
  • directory_server
  • fedora
  • leap

Threat summary

  • Active exploitation appears in 3 classified signals
  • Patch or workaround signal is available
  • 12 mentions across 11 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 3 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • General: 5 classified signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 2 mentions (2026-06-01); latest day: 1
  • 12 total mentions across 11 days

Affected systems

Products
debian_linuxdirectory_serverfedoraleapsambaubuntu_linuxwindows_server_1903windows_server_1909windows_server_2004windows_server_2008

13 versions affected across 15 products

Deep dive

Activity timeline12 mentions / 11d
01122Mentions · 2026-02-20: 1Mentions · 2026-03-04: 1Mentions · 2026-03-20: 1Mentions · 2026-05-07: 1Mentions · 2026-05-15: 1Mentions · 2026-05-17: 1Mentions · 2026-05-29: 1Mentions · 2026-06-01: 2Mentions · 2026-06-15: 1Mentions · 2026-06-26: 1Mentions · 2026-09-30: 1Active Exploitation · 2026-02-20: 1Active Exploitation · 2026-06-01: 1Active Exploitation · 2026-06-15: 1Patch / Workaround · 2026-05-17: 1Patch / Workaround · 2026-05-29: 1Patch / Workaround · 2026-06-01: 1Technical Details · 2026-03-20: 1Technical Details · 2026-05-17: 1Technical Details · 2026-06-01: 2Technical Details · 2026-06-26: 102-2003-0403-2005-0705-1505-1705-2906-0106-1506-2609-30
Signal classification4 categories
General
545.5%
Active Exploitation
327.3%
Disclosure
218.2%
Patch
19.1%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-201
Active Exploitation1
2026-03-041
General1
2026-03-201
General1
2026-05-071
General1
2026-05-151
General1
2026-05-171
Disclosure1
2026-05-291
Patch1
2026-06-012
Active Exploitation1Disclosure1
2026-06-151
Active Exploitation1
2026-06-261
General1
Full discourse12 posts
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    أكيد سمعتوا الأسبوع الماضي عن ثغرة Netlogon من مايكروسوفت (CVE-2026-41089) بشرح في هالتغريدة الخدمة المصابة، وش خطورة الثغرة، وليش لازم تتحدث بسرعة. 📍 وش هي Netlogon؟ ببساطة، Netlogon هي الخدمة المسؤولة عن عملية “الثقة” بين الأجهزة والـ (Domain Controller) في بيئة (Active Directory). تخيلها مثل حارس أمن في مبنى. كل ما جا موظف، يتأكد من بطاقته، يسجل دخوله، ويتأكد إنه فعلاً من ضمن الشركة. هذي تقريباً وظيفة Netlogon في عالم ويندوز. شغلها الفعلي يشمل: 🔹 تأكيد هوية المستخدمين والأجهزة لما يسجلون دخول 🔹 إدارة حسابات الثقة للأجهزة (Machine Trust Accounts) 🔹 الحفاظ على العلاقة بين الجهاز والـ (Domain Controller) 🔹 إدارة قنوات الاتصال المؤمنة بين الأجهزة والـ (DC) 🔹 دعم علاقات الثقة بين الـ (Domain Controllers) والدومينات لو هذي الخدمة تعطلت أو اخترقت، بتتاثر كامل بيئة (Active Directory). 📍 البروتوكول اللي يستخدمه Netlogon هو (Microsoft Netlogon Remote Protocol) MS-NRPC هذا البروتوكول يستخدم (RPC) للتواصل بين الأجهزة والـ (Domain Controller). وغالباً يظهر عبر: 🔹 منفذ 135 الخاص بـ (RPC Endpoint Mapper) 🔹 أو (RPC over SMB) عبر منفذ 445 حسب البيئة 📍 الثغرة الجديدة CVE-2026-41089 مايكروسوفت أعلنت عنها يوم 12 مايو 2026 ضمن تحديثات (Patch Tuesday). تقييمها: (CVSS) 9.8 من 10 نوع الثغرة: (Stack-based Buffer Overflow) في خدمة Netlogon. يعني فيه خلل في طريقة تعامل الخدمة مع بيانات قادمة عبر الشبكة. إذا أرسل المهاجم بيانات مصممة بطريقة معينة، ممكن يصير تجاوز في الذاكرة يؤدي إلى تنفيذ كود عن بعد. 📍 وش معنى Stack-based Buffer Overflow؟ ببساطة، البرنامج لما يستقبل بيانات من الشبكة، يحطها في مساحة محددة داخل الذاكرة اسمها (Stack). تخيلها مثل رف صغير مخصص لكمية معينة من الملفات. لو المهاجم أرسل بيانات أكبر من المساحة المتوقعة، البيانات الزائدة ممكن تكتب فوق أجزاء ثانية في الذاكرة. في بعض الحالات، هذا النوع من الأخطاء يسمح بتغيير مسار تنفيذ البرنامج وتشغيل أوامر غير متوقعة. مو كل (Buffer Overflow) سهل استغلاله، لأن الأنظمة الحديثة فيها حمايات، لكنه يظل من أخطر أنواع ثغرات الذاكرة. 📍 سبب خطورة الثغرة ما تحتاج تسجيل دخول (Unauthenticated) يعني المهاجم ما يحتاج يكون عنده حساب ولا كلمة مرور. ما تحتاج تفاعل من المستخدم (No User Interaction) ما تحتاج أحد يضغط على رابط أو يفتح ملف. تشتغل عن بعد (Remote) إذا المهاجم يقدر يوصل للـ (Domain Controller) عبر الشبكة، معناته يقدر يستغل الثغرة ( نظرياً حتى الان) تعقيد الاستغلال منخفض حسب تقييم (CVSS) 📍 الأنظمة المتأثرة كل إصدارات (Windows Server) التي تعمل كـ (Domain Controller) ضمن الإصدارات المتأثرة: 🔹 Windows Server 2012 / 2012 R2 🔹 Windows Server 2016 🔹 Windows Server 2019 🔹 Windows Server 2022 🔹 Windows Server 2025 📍 مقارنة مع Zerologon CVE-2020-1472 كثير قارنوها بثغرة (Zerologon) الشهيرة. الفرق التقني مهم: 🔹 Zerologon كانت ثغرة في تصميم التشفير داخل بروتوكول Netlogon (Cryptographic flaw) 🔹 CVE-2026-41089 ثغرة في معالجة الذاكرة (Memory Corruption) Zerologon كانت أسهل نسبياً في الاستغلال لأنها قائمة على عيب تشفيري واضح. أما الثغرة الحالية فتحتاج بناء (Exploit) لـ (Buffer Overflow)، وهذا أصعب تقنياً، لكنه مو مستحيل. الاختلاف في التقنية، لكن القاسم المشترك هو: الخطر على الـ (Domain Controller) بدون تسجيل دخول. 📍 مايكروسوفت قالت ان احتمالية الاستغلال بأنها “أقل احتمالاً” Exploitation Less Likely ✋ لكن لا تبني قرارك الأمني على هذي العبارة وحدها اصلا من يثق في ماتقول مايكروسفت؟ حتى لو ما فيه استغلال علني حالياً، تجاهل التحديث مخاطرة غير منطقية. خصوصاً إن الثغرات اللي تمس خدمات حساسة مثل Netlogon تتحول غالباً لهدف جذاب للباحثين والمهاجمين. اتمنى ان التغريده كانت مفيده وممتعه

    Post summary

    The tweet announces Microsoft's CVE‑2026‑41089, explains the high‑severity stack‑based buffer overflow in Netlogon, lists affected systems and Microsoft’s patch, but does not present PoC or active exploitation evidence.

    081462011.7K
    50.0K followersView on X
  • Charles Quin@CharlessQuinn
    General

    I thought I'd spend a weekend studying Zerologon (CVE-2020-1472). It turned into 2+ months of reverse engineering. The result: • 700+ pages of technical research • 6 CVEs analyzed • 15+ detection rules • Full exploit chain (documented) • Crypto deep dive • Patch diff analysis • Incident response playbook The most terrifying part? A single line of code. RtlZeroMemory(IV, 16); Instead of: BCryptGenRandom(...); That tiny mistake reduced entropy enough to give attackers a 1/256 chance of compromising a Domain Controller. No credentials. No phishing. No brute force. Just broken cryptography. Everything is documented—from the Netlogon protocol to the cryptographic flaw, exploit development (educational), detection engineering, and mitigation. The exploit source is intentionally private—for now. I believe research should educate before it enables abuse. If you work with Active Directory, Windows internals, offensive security, or detection engineering, you might find it useful. GitHub 👇 https://github.com/CharlesQuinnDev/Cases/blob/Zerologon-Netlogon-56/Case-Doc.md Reposts are appreciated if you enjoy deep technical research. #CyberSecurity #ActiveDirectory #Windows #RedTeam #BlueTeam #DetectionEngineering #ReverseEngineering #CVE #Zerologon

    Post summary

    A comprehensive technical study of Zerologon (CVE‑2020‑1472) that documents the vulnerability, exploit chain, and detection/mitigation strategies but does not publicly release any PoC or exploit code.

    11013163
    42 followersView on X
  • Alice Sn0w •ᴗ•@Sn0wAlice
    Active Exploitation

    4/ Leur arsenal ressemble à un manuel de red team : • Carbanak • Cobalt Strike • Mimikatz • Lizar (leur loader maison) Initial access via Zerologon (CVE-2020-1472) et ProxyShell (CVE-2021-31207).

    Post summary

    The statement identifies a threat actor’s toolchain and confirms that Zerologon and ProxyShell are being leveraged for initial access, indicating active exploitation, but no PoC, patch, or detailed technical data is provided.

    10010107
    1.6K followersView on X
  • CiberBaur@BotBauR
    Active Exploitation

    Acaba de confirmarse: La vulnerabilidad crítica de Windows Netlogon, conocida como Zerologon (CVE-2020-1472), está siendo explotada en ataques, lo que podría permitir a los atacantes acceder a sistemas sin autorización. El Centre for Cybersecurity Belgium (CCB) advirtió que esta vulnerabilidad, que afecta a controladores de dominio Windows, permite la ejecución remota de código (RCE) y la toma de control total del dominio. Las versiones afectadas incluyen Windows Server 2008, 2008 R2, 2012, 2012 R2, 2016 y 2019. La gravedad de esta vulnerabilidad es crítica, con un CVSS v3 base score de 10.0. Los atacantes pueden explotar esta vulnerabilidad para acceder a sistemas sin autorización y tomar el control del dominio. El estado actual es que ya se observa explotación activa en ataques reales. Es importante que los administradores de sistemas revisen sus sistemas y apliquen los parches necesarios para evitar ser víctimas de estos ataques. ¿Estás en riesgo? Revisa esto: asegúrate de que tus sistemas estén actualizados y que hayas aplicado el parche para la vulnerabilidad Zerologon. https://www.bleepingcomputer.com/news/microsoft/critical-windows-netlogon-remote-code-execution-flaw-now-exploited-in-attacks/

    Post summary

    The article reports that Windows Netlogon Zerologon (CVE‑2020‑1472) is being actively exploited in real attacks, emphasizes the critical CVSS score and RCE nature, and urges administrators to apply the available patch to mitigate the risk.

    0101086
    329 followersView on X
  • DFIR Radar@DFIR_Radar

    Rhysida hit Berlin via phishing, exfiltrating 5.7TB; Iranian 🇮🇷 Nimbus Manticore trojanized colorized_terminal in fake coding challenges. Hunt node_modules for colorized_terminal; flag CVE-2020-1472 if unpatched. #DFIR_Radar https://t.co/kvz5HBnm56

    10000145
    2.0K followersView on X
  • Adam@seoscottsdale
    Disclosure

    2/5 One crafted network packet = SYSTEM-level code execution on a DC. No login, no prior access needed. This is “domain admin in one packet.” Think full AD takeover, credential dumping, golden tickets, ransomware — the works. Spiritual successor to Zerologon (CVE-2020-1472).

    Post summary

    The text announces a new vulnerability allowing SYSTEM-level code execution on a domain controller via a single crafted packet, with no prior access required, positioning it as a serious AD takeover vector.

    1000091
    12.4K followersView on X
  • @djrevmoon.bsky.social@djrevmoon
    Patch

    Only minor gripe was they took nearly 18 months to fix and their initial triage was very lazy. But it was a major protocol fix that needed coordination with many vendors and we were not in it for the bounty. This was for CVE-2020-1472 (Zerologon).

    Post summary

    The post comments on the delayed triage and 18‑month patch process for CVE‑2020‑1472 (Zerologon), noting a major protocol fix that required inter‑vendor coordination, but it provides no technical or exploitation details.

    0001096
    592 followersView on X
  • truemorgan@_truemorgan
    General

    Windows: CVE-2017-0144 CVE-2017-0145 CVE-2008-4250 CVE-2019-0708 CVE-2020-1472 CVE-2021-34527 CVE-2021-26855 CVE-2020-1350 CVE-2003-0352 CVE-2014-6324 CVE-2017-0199 CVE-2021-40444 CVE-2022-30190 CVE-2021-31166 CVE-2022-21907 CVE-2019-1182 CVE-2019-1181 CVE-2020-0601 CVE-2023-29363 CVE-2023-32014 CVE-2025-24985 CVE-2025-24993 CVE-2024-38063 CVE-2022-34718 CVE-2021-26857 CVE-2021-36934 CVE-2022-37969 CVE-2022-41033 CVE-2022-38028 CVE-2023-28252 CVE-2024-26169 CVE-2025-29824 CVE-2025-30400 CVE-2025-32701 CVE-2025-32706 CVE-2016-0099 CVE-2020-1048 CVE-2017-8529 CVE-2020-0688 CVE-2021-42287 CVE-2021-42278 CVE-2022-26923 CVE-2021-34523 CVE-2021-31207 CVE-2026-32202 CVE-2017-5754 CVE-2017-5753 CVE-2018-3639 CVE-2019-11135 CVE-2018-3620

    Post summary

    A list of Windows CVE identifiers with no additional context or commentary.

    10000106
    15 followersView on X
  • David@davidsheyi
    General

    9/ CVE-2020-1472: Zerologon enables attackers to gain domain admin privileges. Monitor for SMB traffic anomalies to detect exploitation. #TrafficAnalysis #PacketAnalysis

    Post summary

    The tweet references CVE-2020-1472 (Zerologon) and advises monitoring SMB traffic anomalies to detect potential exploitation, but provides no detailed technical or defensive information.

    1000022
    555 followersView on X
  • SecLab Brasil@SecLabBrasil
    General

    ZeroLogon (CVE-2020-1472): CVSS 10.0 - o maximo possivel 1 exploit = Domain Admin instantaneo Muitos DCs ainda nao patcheados Como testar + como mitigar

    Post summary

    The post notes ZeroLogon's high CVSS score and that many domain controllers remain unpatched, but it lacks specific PoC, exploit details, or mitigation steps.

    0000016
  • alaan@_alaaan_
    General

    Lo de hacer un CVSS 10.0 en el servidor de un centro publico es loco, 14.000 entradas de hashes de cuentas del dominio.... CVE-2020-1472 por cierto

    Post summary

    El texto simplemente menciona el CVE-2020-1472 sin proporcionar detalles adicionales sobre PoC, explotaciones, parches o verificación.

    0000066
    112 followersView on X
  • CVEDatabase.com@cvedatabase
    Active Exploitation

    What’s more dangerous? A) Zero-days B) Unpatched one-year-old CVEs C) Assets you forgot existed Attackers already chose B + C. Example: CVE-2020-1472 (Zerologon) — still exploited in 2026. 🔗 Why it still works: https://cvedatabase.com/cve/CVE-2020-1472 #CyberSecurity #VulnerabilityManagement

    Post summary

    The post highlights that CVE-2020-1472 (Zerologon) remains actively exploited in 2026, underscoring the dangers of unpatched, older vulnerabilities and unseen assets.

    0000028
    1 followersView on X
CPE platform detail23 entries

23 of 23 entries

PartVendorProductVersionTarget SWTarget HW
OScanonicalubuntu_linux14.04--
OScanonicalubuntu_linux16.04--
OScanonicalubuntu_linux16.04--
OScanonicalubuntu_linux18.04--
OScanonicalubuntu_linux20.04--
OSdebiandebian_linux9.0--
OSfedoraprojectfedora31--
OSfedoraprojectfedora32--
OSfedoraprojectfedora33--
OSmicrosoftwindows_server_1903---
OSmicrosoftwindows_server_1909---
OSmicrosoftwindows_server_2004---
OSmicrosoftwindows_server_2008r2-x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_20h2---
OSopensuseleap15.1--
OSopensuseleap15.2--
Apporaclezfs_storage_appliance_kit8.8--
Appsambasamba---
Appsynologydirectory_server---

Explore more