ENISA EUVD · EUVD-2020-12346Known-exploited evidence recordedAn elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run a specially crafted application on a device on the network.
To exploit the vulnerability, an unauthenticated attacker would be required to use MS-NRPC to connect to a domain controller to obtain domain administrator access.
Microsoft is addressing the vulnerability in a phased two-part rollout. These updates address the vulnerability by modifying how Netlogon handles the usage of Netlogon secure channels.
For guidelines on how to manage the changes required for this vulnerability and more information on the phased rollout, see How to manage the changes in Netlogon secure channel connections associated with CVE-2020-1472 (updated September 28, 2020).
When the second phase of Windows updates become available in Q1 2021, customers will be notified via a revision to this security vulnerability. If you wish to be notified when these updates are released, we recommend that you register for the security notifications mailer to be alerted of content changes to this advisory. See Microsoft Technical Security Notifications.
Official EUVD record ↗Canadian Centre for Cyber Security · English · AV21-073Microsoft security advisory – February 2021 monthly rollupOn 9 February 2021 Microsoft published Security Updates to address vulnerabilities in multiple products. Included were critical updates for the following:
Included in this update is the default enablement of Domain Controller enforcement mode, which blocks insecure NRPC connections from non-compliant devices. This update also addresses a vulnerability in Windows Win32k which may result in an escalation of privilege resulting in full system compromise. Microsoft has confirmed this vulnerability has been detected in the wild.
Official advisory ↗Canadian Centre for Cyber Security · English · AL20-025Continued Exploitation by APT Actors of Multiple VulnerabilitiesOn 20 October 2020 the National Security Agency (NSA) published a Cyber Security Advisory (U/OO/179811-20) [ 1 ] detailing recent malicious activity targeting US information systems. The Cyber Centre is aware that many Canadian entities operate similar information systems in Canada. These information systems and the networks linking them are critical components in today’s interconnected world. Relied upon by governments, utilities, small businesses and individuals worldwide, they require regular updates to secure them from malicious activity that targets known or recently discovered vulnerabilities. While manufacturers work hard to provide updates for vulnerabilities, these updates are not always applied in a timely manner by consumers.
The Cyber Centre continues to receive reports [ 2 ] [ 5 ] [ 6 ] of persistent exploitation of known vulnerabilities. Much of the reported activity appears to be the result of well-coordinated Advanced Persistent Threat (APT) actors targeting systems such as unpatched remote access services, security appliances and application servers.
The Cyber Centre recommends that individuals and corporations review the following security guidance to better protect their information systems:
Cyber Centre Publications [ 3 ]
Top 10 IT Security Actions to Protect Internet Connected Networks and Information (ITSM.10.189) [ 4 ]
NSA report U/OO/179811-20 [ 1 ] - A comprehensive list of vulnerabilities impacting information systems as well as general and tailored recommendations.
Should organizations identify similar activity to that described in the referenced Advisories and Alerts, recipients are encouraged to contact the Cyber Centre by email ( contact@cyber.gc.ca ) or by telephone ( 1-833-CYBER-88 or 1-833-292-3788 ).
Official advisory ↗Canadian Centre for Cyber Security · English · AL20-022Microsoft Netlogon Elevation of Privilege Vulnerability - CVE-2020-1472 - update 1The Cyber Centre has become aware of recently published proofs of concept exploit code related to CVE-2020-1472, a Netlogon elevation of privilege vulnerability. The Cyber Centre strongly recommends that organizations immediately patch vulnerable systems.
Official advisory ↗Cyber Security Agency of Singapore · English · CSA-SB-20200819Security Bulletin 19 Aug 2020The Cyber Security Agency of Singapore included this CVE in its official Security Bulletin 19 Aug 2020, published on 19 August 2020. Open the linked bulletin for the product, severity and reference information published in that issue.
Official advisory ↗CERT-FR · French · CERTFR-2021-AVI-772Multiples vulnérabilités dans les produits Schneidere.org/CVERecord?id=CVE-2019-11135
Référence CVE CVE-2020-0601
https://www.cve.org/CVERecord?id=CVE-2020-0601
Référence CVE CVE-2020-0609
https://www.cve.org/CVERecord?id=CVE-2020-0609
Référence CVE CVE-2020-0610
https://www.cve.org/CVERecord?id=CVE-2020-0610
Référence CVE CVE-2020-0796
https://www.cve.org/CVERecord?id=CVE-2020-0796
Référence CVE CVE-2020-0938
https://www.cve.org/CVERecord?id=CVE-2020-0938
Référence CVE CVE-2020-1020
https://www.cve.org/CVERecord?id=CVE-2020-1020
Référence CVE CVE-2020-1350
https://www.cve.org/CVERecord?id=CVE-2020-1350
Référence CVE CVE-2020-13987
https://www.cve.org/CVERecord?id=CVE-2020-13987
Référence CVE CVE-2020-1472
https://www.cve.org/CVERecord?id=CVE-2020-1472
Référence CVE CVE-2020-17438
https://www.cve.org/CVERecord?id=CVE-2020-17438
Référence CVE CVE-2021-22800
https://www.cve.org/CVERecord?id=CVE-2021-22800
Référence CVE CVE-2021-22801
https://www.cve.org/CVERecord?id=CVE-2021-22801
Référence CVE CVE-2021-22802
https://www.cve.org/CVERecord?id=CVE-2021-22802
Référence CVE CVE-2021-22803
https://www.cve.org/CVERecord?id=CVE-2021-22803
Référence CVE CVE-2021-22804
https://www.cve.org/CVERecord?id=CVE-2021-22804
Référence CVE CVE-2021-22805
https://www.cve.org/CVERecord?id=CVE-2021-22805
Référence CVE CVE-2021-22806
https://www.cve.org/CVERecord?id=C
Official advisory ↗CERT-FR · French · CERTFR-2021-AVI-638Multiples vulnérabilités dans Juniper Junos Spaced?id=CVE-2020-10029
Référence CVE CVE-2020-10543
https://www.cve.org/CVERecord?id=CVE-2020-10543
Référence CVE CVE-2020-10878
https://www.cve.org/CVERecord?id=CVE-2020-10878
Référence CVE CVE-2020-12723
https://www.cve.org/CVERecord?id=CVE-2020-12723
Référence CVE CVE-2020-13765
https://www.cve.org/CVERecord?id=CVE-2020-13765
Référence CVE CVE-2020-14318
https://www.cve.org/CVERecord?id=CVE-2020-14318
Référence CVE CVE-2020-14323
https://www.cve.org/CVERecord?id=CVE-2020-14323
Référence CVE CVE-2020-14351
https://www.cve.org/CVERecord?id=CVE-2020-14351
Référence CVE CVE-2020-14364
https://www.cve.org/CVERecord?id=CVE-2020-14364
Référence CVE CVE-2020-1472
https://www.cve.org/CVERecord?id=CVE-2020-1472
Référence CVE CVE-2020-15862
https://www.cve.org/CVERecord?id=CVE-2020-15862
Référence CVE CVE-2020-16092
https://www.cve.org/CVERecord?id=CVE-2020-16092
Référence CVE CVE-2020-1971
https://www.cve.org/CVERecord?id=CVE-2020-1971
Référence CVE CVE-2020-1983
https://www.cve.org/CVERecord?id=CVE-2020-1983
Référence CVE CVE-2020-25211
https://www.cve.org/CVERecord?id=CVE-2020-25211
Référence CVE CVE-2020-25645
https://www.cve.org/CVERecord?id=CVE-2020-25645
Référence CVE CVE-2020-25656
https://www.cve.org/CVERecord?id=CVE-2020-25656
Référence CVE CVE-2020-25705
https://www.cve.org/CVERecord?id=CVE-2
Official advisory ↗CERT-FR · French · CERTFR-2021-AVI-589Multiples vulnérabilités dans Juniper Junos Space Log Collectord?id=CVE-2020-12243
Référence CVE CVE-2020-12321
https://www.cve.org/CVERecord?id=CVE-2020-12321
Référence CVE CVE-2020-12351
https://www.cve.org/CVERecord?id=CVE-2020-12351
Référence CVE CVE-2020-12723
https://www.cve.org/CVERecord?id=CVE-2020-12723
Référence CVE CVE-2020-12825
https://www.cve.org/CVERecord?id=CVE-2020-12825
Référence CVE CVE-2020-14305
https://www.cve.org/CVERecord?id=CVE-2020-14305
Référence CVE CVE-2020-14331
https://www.cve.org/CVERecord?id=CVE-2020-14331
Référence CVE CVE-2020-14372
https://www.cve.org/CVERecord?id=CVE-2020-14372
Référence CVE CVE-2020-14385
https://www.cve.org/CVERecord?id=CVE-2020-14385
Référence CVE CVE-2020-1472
https://www.cve.org/CVERecord?id=CVE-2020-1472
Référence CVE CVE-2020-15862
https://www.cve.org/CVERecord?id=CVE-2020-15862
Référence CVE CVE-2020-25632
https://www.cve.org/CVERecord?id=CVE-2020-25632
Référence CVE CVE-2020-25643
https://www.cve.org/CVERecord?id=CVE-2020-25643
Référence CVE CVE-2020-25647
https://www.cve.org/CVERecord?id=CVE-2020-25647
Référence CVE CVE-2020-25705
https://www.cve.org/CVERecord?id=CVE-2020-25705
Référence CVE CVE-2020-27749
https://www.cve.org/CVERecord?id=CVE-2020-27749
Référence CVE CVE-2020-27779
https://www.cve.org/CVERecord?id=CVE-2020-27779
Référence CVE CVE-2020-28374
https://www.cve.org/CVERecord?id=C
Official advisory ↗CERT-FR · French · CERTFR-2021-AVI-299Multiples vulnérabilités dans Oracle SystemsDe multiples vulnérabilités ont été découvertes dans Oracle Systems.
Elles permettent à un attaquant de provoquer une exécution de code
arbitraire à distance, une atteinte à l'intégrité des données et une
atteinte à la confidentialité des données.
Official advisory ↗CERT-FR · French · CERTFR-2020-AVI-579Vulnérabilité dans SambaUne vulnérabilité a été découverte dans le logiciel Samba. Elle permet à
un attaquant de provoquer une élévation de privilèges si le serveur
Samba est configuré pour être contrôleur de domaine (de type 'NT4' ou
Active Directory).
La configuration par défaut de Samba v4.8 (et ultérieures) permet de se
prémunir contre cette vulnérabilité.
Official advisory ↗CERT-FR · French · CERTFR-2020-AVI-501Multiples vulnérabilités dans Microsoft Windows.cve.org/CVERecord?id=CVE-2020-1378
Référence CVE CVE-2020-1379
https://www.cve.org/CVERecord?id=CVE-2020-1379
Référence CVE CVE-2020-1383
https://www.cve.org/CVERecord?id=CVE-2020-1383
Référence CVE CVE-2020-1417
https://www.cve.org/CVERecord?id=CVE-2020-1417
Référence CVE CVE-2020-1459
https://www.cve.org/CVERecord?id=CVE-2020-1459
Référence CVE CVE-2020-1464
https://www.cve.org/CVERecord?id=CVE-2020-1464
Référence CVE CVE-2020-1466
https://www.cve.org/CVERecord?id=CVE-2020-1466
Référence CVE CVE-2020-1467
https://www.cve.org/CVERecord?id=CVE-2020-1467
Référence CVE CVE-2020-1470
https://www.cve.org/CVERecord?id=CVE-2020-1470
Référence CVE CVE-2020-1472
https://www.cve.org/CVERecord?id=CVE-2020-1472
Référence CVE CVE-2020-1473
https://www.cve.org/CVERecord?id=CVE-2020-1473
Référence CVE CVE-2020-1474
https://www.cve.org/CVERecord?id=CVE-2020-1474
Référence CVE CVE-2020-1475
https://www.cve.org/CVERecord?id=CVE-2020-1475
Référence CVE CVE-2020-1477
https://www.cve.org/CVERecord?id=CVE-2020-1477
Référence CVE CVE-2020-1478
https://www.cve.org/CVERecord?id=CVE-2020-1478
Référence CVE CVE-2020-1479
https://www.cve.org/CVERecord?id=CVE-2020-1479
Référence CVE CVE-2020-1480
https://www.cve.org/CVERecord?id=CVE-2020-1480
Référence CVE CVE-2020-1484
https://www.cve.org/CVERecord?id=CVE-2020-1484
Ré
Official advisory ↗NBSZ-NKI · Hungarian · cve-2020-1472CVE-2020-1472Kritikus
Official advisory ↗JVN iPedia · Japanese · JVNDB-2020-008530複数の Microsoft Windows 製品における権限昇格の脆弱性複数の Microsoft Windows 製品には、権限を昇格される脆弱性が存在します。 ベンダは、本脆弱性を「Netlogon の特権の昇格の脆弱性」として公開しています。
Official advisory ↗KISA KrCERT/CC · Korean · KNVD-5271MS 2월 보안 위협에 따른 정기 보안 업데이트 권고원격 코드 실행 취약성
Microsoft Office Excel
CVE-2021-24067
Microsoft Excel 원격 코드 실행 취약성
Microsoft Office SharePoint
CVE-2021-24072
Microsoft SharePoint Server 원격 코드 실행 취약성
Microsoft Office SharePoint
CVE-2021-24071
Microsoft SharePoint 정보 유출 취약성
Microsoft Office SharePoint
CVE-2021-24066
Microsoft SharePoint 원격 코드 실행 취약성
Microsoft Office SharePoint
CVE-2021-1726
Microsoft SharePoint 스푸핑 취약성
Microsoft Teams
CVE-2021-24114
Microsoft Teams iOS Information Disclosure Vulnerability
Microsoft Windows Codecs Library
CVE-2021-24091
Windows 카메라 코덱 팩 원격 코드 실행 취약성
Microsoft Windows Codecs Library
CVE-2021-24081
Microsoft Windows 코덱 라이브러리 원격 코드 실행 취약성
Netlogon
CVE-2020-1472
NetLogon 권한 상승 취약성
Role: DNS Server
CVE-2021-24078
Windows DNS 서버 원격 코드 실행 취약성
Role: Hyper-V
CVE-2021-24076
Microsoft Windows VMSwitch 정보 유출 취약성
Role: Windows Fax Service
CVE-2021-24077
Windows Fax 서비스 원격 코드 실행 취약성
Role: Windows Fax Service
CVE-2021-1722
Windows Fax 서비스 원격 코드 실행 취약성
Skype for Business
CVE-2021-24099
비즈니스용 Skype 서비스 거부 취약성
Skype for Business
CVE-2021-24073
비즈니스용 Skype 및 Lync 스푸핑 취약성
SysInternals
CVE-2021-1733
Sysinternals PsExec 권한 상승 취약성
System Center
CVE-2021-1728
System Center Operations Manager 권한 상승 취약성
Visual Studio
CVE-2021-1639
Visual Studio Code 원격 코드 실행 취약성
Visual Studio Code
CVE-2021-26700
Visual Studio Code npm-sc
Official advisory ↗KISA KrCERT/CC · Korean · KNVD-5251주요 보안 취약점 업데이트를 재확인 하세요!!재확인 하세요!! 2021.01.05
##### □ 개요
o `20년 보안공지 된 취약점 중 업데이트 적용에 대한 재확인이 필요한 주요 취약점 리스트
※ 미국 NSA 발표, 랜섬웨어 유포에 악용된 취약점 등 이슈화 된 취약점 선정
##### □ 주요 내용
No
구분
CVE번호
제조사
제품명
취약점 종류
패치정보 및 보안공지
1
네트워크
CVE-2019-15978 외 10개
Cisco
Data Center Network Manager
명령어 삽입 취약점 등
[1]
2
네트워크
CVE-2019-19781
Citrix
ADC, Gateway,SDWAN-WANOP
임의코드 실행 취약점
[2]
3
네트워크
CVE-2020-11896
Cisco
ASR 500,5500
원격코드 실행 취약점
[3]
4
운영체제
CVE-2020-7247
-
OpenSMTPD
원격코드 실행 취약점
[4]
5
운영체제
CVE-2020-0674
MS
인터넷 익스플로러
원격코드 실행 취약점
[5]
6
운영체제
CVE-2020-0688
MS
윈도우 Exchange 서버
원격코드 실행 취약점
[6]
7
운영체제
CVE-2020-0796
MS
윈도우
SMBv3 원격코드 실행 취약점
[7]
8
운영체제
CVE-2019-14287
유닉스/리눅스
-
sudo 명령어 취약점
[8]
9
운영체제
CVE-2020-1472
MS
윈도우 서버
Netlogon 권한상승 취약점
[9]
10
가상화
CVE-2020-3943 외 2개
VMware
vRealize Operations
임의코드 실행 취약점 등
[10]
11
가상화
CVE-2020-3952
VMware
vCenter Server
정보유노출 취약점
[11]
12
웹서버
CVE-2020-1938
Apache
Tomcat
원격코드 실행 취약점
[12]
13
보안솔루션
CVE-2020-7845
지란지교시큐리티
스팸스나이퍼
버퍼오버플로우 취약점
[13]
14
보안솔루션
CVE-2020-25043 외 11개
Kaspersky 등 7개사
백신프로그램
임의파일 삭제 취약점 등
[14]
15
원격협업
CVE-2020-6109 외 1개
Zoom
Zoom
임의파일 쓰기 취약점
[15]
16
원격협업
CVE-2020-8207
Citrix
Workspace
권한 상승 취약점
[16]
17
원격협업
CVE-2020-13699
Team Viewer
TeamViewer
원격코드 실행 취약점
[17]
18
IoT
CVE-2020-10173 외 10개
LG 등 9개사
공유기, IP카메라 등
악성코드 유포, DDoS
[18]
19
복합기
CVE-2018-5924
HP
HP DesignJet
원격코드 실행 취약점
[19]
20
솔루션
CVE-20
Official advisory ↗KISA KrCERT/CC · Korean · KNVD-5212MS 윈도우 서버 Netlogon 취약점 보안 업데이트 권고 (2차)CVE-2020-1472
윈도우 서버의 Netlogon 권한상승 취약점(CVE-2020-1472)에 대한 최신 업데이트가 적용되어 있지 않은 경우 공격 위험에 노출
Official advisory ↗KISA KrCERT/CC · Korean · KNVD-5219해킹 공격에 악용되는 취약점 업데이트 권고#### 해킹 공격에 악용되는 취약점 업데이트 권고 2020.10.22
##### □ 개요
o 美 국가안보국(NSA), 해커들이 사이버 공격에 악용하는 25개의 취약점 리스트 발표 [1]
o 공격자는 해당 취약점을 악용하여 침해사고를 발생시킬 수 있으므로, 기업 담당자 및 해당 시스템을 이용중인 사용자는 최신 버전으로 업데이트 권고
##### □ 주요 내용
제조사
제품
CVE ID
내용
Microsoft
윈도우즈
CVE-2019-0708 [2]
공격자가 특별하게 조작된 RDP 패킷을 전송하여 피해 시스템에 임의 코드를 실행할 수 있는 취약점
CVE-2020-1040 [3]
공격자가 NTLM MIC(메시지 무결성 검증)을 우회하여 중간자공격(MITM)이 가능한 취약점
CVE-2020-0601 [4]
암호화 인증서를 검증하는 API에서 발생하는 중간자공격(MITM)이 가능한 취약점
CVE-2019-0803 [5]
메모리의 객체 처리가 미흡하여 발생하는 권한상승 취약점
CVE-2020-1472 [6]
Netlogon 프로토콜의 취약한 암호화 운영모드 사용으로 발생하는 권한상승 취약점
윈도우
서버
CVE-2020-1350 [7]
DNS로 운영되는 Windows 서버에서 요청값에 대한 처리가 미흡하여 발생하는 원격코드실행 취약점
윈도우
Exchange
서버
CVE-2020-0688 [8]
메모리의 객체에 대한 처리가 미흡하여 발생하는 원격코드실행 취약점
Oracle
WebLogic Server
CVE-2015-4852 [9]
조작된 자바 객체를 역직렬화하여 발생하는 임의코드실행 취약점
Coherence
CVE-2020-2555 [10]
조작한 T3 프로토콜의 request를 허용 및 역직렬화하여 발생하는 원격코드실행 취약점
Citrix
ADC,
Gateway,
SDWAN- WANOP
CVE-2019-19781 [11]
공격자가 인증을 우회하여 임의코드를 실행할 수 있는 취약점
CVE-2020-8193, 8195, 8196 [12]
허가되지 않은 사용자가 특정 URL에접근 가능하여 발생하는 정보노출 취약점
Atlassian
Confluence
Server
CVE-2019-3396 [13]
Widget Connector macro에서 발생하는 경로탐색 및 원격코드실행 취약점
Crowd,
Crowd
Data
Center
CVE-2019-115
Official advisory ↗KISA KrCERT/CC · Korean · KNVD-5198Samba 취약점 보안 업데이트 권고Samba AD(Active Directory) DC(Domain Controller)에서 Netlogon 프로토콜의 취약한 암호화 운영모드 사용으로 발생하는 권한상승 취약점(CVE-2020-1472) [2]
Official advisory ↗KISA KrCERT/CC · Korean · KNVD-5195MS 윈도우 서버 Netlogon 취약점 보안 업데이트 권고 (1차)윈도우 서버의 Netlogon에서 취약한 암호화 운영모드를 사용하여 발생하는 권한상승 취약점(CVE-2020-1472) [2]
Official advisory ↗KISA KrCERT/CC · Korean · KNVD-5191MS 8월 보안 위협에 따른 정기 보안 업데이트 권고영향 : 원격코드실행
o 중요도 : 긴급
o 관련 KB번호
- 4565349, 4565351, 4566782, 4571692, 4571694, 4571709, 4571741
##### □ 해결책
o 영향 받는 소프트웨어를 이용하는 경우 마이크로소프트사의 보안 패치 적용
2. Windows Server 2019, Windows Server 2016, Server Core 설치(2019, 2016, v1909, v1903, v1803) 보안 업데이트
##### □ 설명
o 공격자가 특수하게 제작된 악성 응용 프로그램을 실행할 경우, 원격코드실행을 허용하는 취약점
o 관련취약점 :
- 원격코드실행 취약점(CVE-2020-1339, CVE-2020-1379, CVE-2020-1473, CVE-2020-1477, CVE-2020-1478, CVE-2020-1492, CVE-2020-1520, CVE-2020-1525, CVE-2020-1554, CVE-2020-1557, CVE-2020-1558, CVE-2020-1561, CVE-2020-1562, CVE-2020-1564)
- 권한상승 취약점(CVE-2020-1337, CVE-2020-1377, CVE-2020-1378, CVE-2020-1417, CVE-2020-1467, CVE-2020-1470, CVE-2020-1472, CVE-2020-1475, CVE-2020-1479, CVE-2020-1480, CVE-2020-1484, CVE-2020-1486, CVE-2020-1488, CVE-2020-1489, CVE-2020-1490, CVE-2020-1509, CVE-2020-1511, CVE-2020-1513, CVE-2020-1515, CVE-2020-1516, CVE-2020-1517, CVE-2020-1518, CVE-2020-1519, CVE-2020-1521, CVE-2020-1522, CVE-2020-1524, CVE-2020-1526, CVE-2020-1527, CVE-2020-1528, CVE-2020-1529, CVE-2020-1530, CVE-2020-1531, CVE-2020-1533, CVE-2020-1534, CVE-2020-1537, CVE-2020-1538, CVE-2020-1549, CVE-2020-1550, CVE-2020-1552, CVE-2020-1553, CVE-2020-1556, CVE-2020-1565, CVE-2020-1566, CVE-2020-1579, CVE-2020-1584, CVE-2020-1587)
- 서비스거부 취약점(CVE-2020-1466)
- 스푸핑 취약점(CVE-2020-1464)
- 정보노출 취약점(
Official advisory ↗