CVE-2020-1472β€”Microsoft Netlogon Privilege Escalation Vulnerability

PUBLISHEDvulnerability record
2021-11-03 Β· last modified December 22, 2025

Metadata

CVE ID:
CVE-2020-1472
Project:
Microsoft
Product:
Netlogon
Date Added:
2021-11-03
Due Date:
2022-05-03
Last Updated:
December 22, 2025

Vulnerability Name

Microsoft Netlogon Privilege Escalation Vulnerability

Description

Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller. An attacker who successfully exploits the vulnerability could run a specially crafted application on a device on the network. The vulnerability is also known under the moniker of Zerologon.

Known To Be Used in Ransomware Campaigns?

Ransomware Status:
KNOWN

Action

Apply updates per vendor instructions.

Additional Notes

Related News Articles

Related Weaknesses