BlackTreeCVE Intelligence
← Back to the CVE catalogue
Full vulnerability report · 2020
CVE-2020-1472High confidence

Microsoft Netlogon Privilege Escalation Vulnerability

Microsoft · Netlogon

5.5MediumCVSS 3.1
Recommended action
Patch now

CISA confirms exploitation in the wild and lists 2022-05-03 as the remediation due date.

Patch available
R
Operational reassessment

Published severity in operational context

Open reassessment dashboard →
Published severityMediumOperational priority:Critical, raised 2 bands.upgradedsince 3 Nov 2021

Evidence used

  • CISA confirms exploitation in the wild.
  • A structured source references public exploit or proof-of-concept material.
  • Exploitation requires an existing local or physical foothold with privileges.
  • EPSS is 99.39% for the current model date.

Compensating controls

  • Validate the affected product branch and deploy the verified fixed release.
  • Restrict local access and enforce least privilege on affected hosts.
  • Increase monitoring for the attack path and post-exploitation behaviour described in the report.

Verification

  1. Confirm that the asset runs Microsoft Netlogon and falls inside the recorded affected range.
  2. Verify the installed build against the product-specific fixed version after deployment.
  3. Validate exposure, authentication requirements and compensating controls in the actual environment.
  4. Reopen this reassessment when CVSS, KEV, EPSS, exploit evidence or remediation changes.
Mitigation target: Within 3 daysRemediation target: Within 90 days

This automated reassessment organises public evidence. It does not know asset exposure, business impact or control effectiveness and does not replace CVSS or a human risk decision.

Distribution package intelligence

Release-specific package status

Alpine, Debian findings are scoped to the named distribution, release and source package. An absent finding does not mean a package is unaffected.

7 package states
Repository candidate not checked

A published vendor fix does not prove that a matching update is enabled and installable on a particular asset. Confirm the local package candidate before scheduling remediation.

Distribution releaseSource packageVendor stateFixed versionEvidence
Alpine v3.23v3.23 · mainsambaVendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.4.12.7-r0Alpine Security Database ↗Source updated 3 Oct 2026
Alpine v3.22v3.22 · mainsambaVendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.4.12.7-r0Alpine Security Database ↗Source updated 3 Oct 2026
Alpine v3.21v3.21 · mainsambaVendor fix publishedAlpine records a security fix at this version. An absent entry does not mean the package is unaffected.4.12.7-r0Alpine Security Database ↗Source updated 3 Oct 2026
Debian trixietrixie · sourcesambaVendor fix publishedDebian records a fixed source-package version for this release.2:4.13.2+dfsg-2Debian Security Tracker ↗Source updated 6 Oct 2026
Debian bookwormbookworm · sourcesambaVendor fix publishedDebian records a fixed source-package version for this release.2:4.13.2+dfsg-2Debian Security Tracker ↗Source updated 6 Oct 2026
Debian forkyforky · sourcesambaVendor fix publishedDebian records a fixed source-package version for this release.2:4.13.2+dfsg-2Debian Security Tracker ↗Source updated 6 Oct 2026
Debian sidsid · sourcesambaVendor fix publishedDebian records a fixed source-package version for this release.2:4.13.2+dfsg-2Debian Security Tracker ↗Source updated 6 Oct 2026
Direct vendor intelligence

Authoritative vendor CSAF and VEX advisories

Structured product status and remediation from the issuing vendor. Product-state explanations are always visible; large lists can be searched or downloaded.

1 current
SEVD-2021-285-05 · CSAF 2.0 · revision 1.0.0 · finalSchneider Electric CPCERTConext™ Advisor & Conext™ Control V2
3 known affected

The vendor explicitly identifies these products as affected by this CVE.

  • Schneider Electric Conext™ Advisor 2 Cloud 2.02 and below
  • Schneider Electric Conext™ Advisor 2 Gateway 1.28.45 and below
  • Schneider Electric Conext™ Control V2 Gateway 2.6 and below
Summary
An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC), aka 'Netlogon Elevation of Privilege Vulnerability'.
Remediation
Version Windows 10 of the Microsoft Windows includes a fix for this vulnerability and is available for download here: • https://www.microsoft.com/en-in/software-download/windows10 • Reboot is required
Optional official sources

National CERT insights
?CERT means Computer Emergency Response Team; CSIRT is the closely related term Computer Security Incident Response Team.

Choose official national sources for this report. Each advisory shows its original language. Your selection is remembered on this device and included in shared links.

Official European source

ENISA European Vulnerability Database

Official EUVD identifiers, advisory evidence and known-exploited context. Missing fields are not treated as evidence of low risk.

1 current
ENISA EUVD identifier

EUVD-2020-12346

EU known exploited

An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run a specially crafted application on a device on the network. To exploit the vulnerability, an unauthenticated attacker would be required to use MS-NRPC to connect to a domain controller to obtain domain administrator access. Microsoft is addressing the vulnerability in a phased two-part rollout. These updates address the vulnerability by modifying how Netlogon handles the usage of Netlogon secure channels. For guidelines on how to manage the changes required for this vulnerability and more information on the phased rollout, see How to manage the changes in Netlogon secure channel connections associated with CVE-2020-1472 (updated September 28, 2020). When the second phase of Windows updates become available in Q1 2021, customers will be notified via a revision to this security vulnerability. If you wish to be notified when these updates are released, we recommend that you register for the security notifications mailer to be alerted of content changes to this advisory. See Microsoft Technical Security Notifications.

EUVD state
Present in the current official mapping
Known exploitation
Recorded by ENISA since 3 Nov 2021. Evidence sources: cisa_kev, eukev_kev.
ENISA score
5.5 · CVSS 3.1
Advisory evidence
16 linked advisory records
Explicit mitigation evidence

Only statements that explicitly mention a fix, patch, update, workaround or mitigation are shown here.

  • csaf_redhat · RHSA-2021:3723Red Hat Security Advisory: samba security, bug fix and enhancement update
  • csaf_opensuse · openSUSE-SU-2020:1526-1Security update for samba
  • csaf_suse · SUSE-SU-2020:2724-1Security update for samba
  • csaf_suse · SUSE-SU-2020:2722-1Security update for samba
  • csaf_suse · SUSE-SU-2020:2721-1Security update for samba
  • csaf_redhat · RHSA-2021:1647Red Hat Security Advisory: samba security, bug fix, and enhancement update
  • csaf_suse · SUSE-SU-2020:2730-1Security update for samba
  • csaf_suse · SUSE-SU-2020:2719-1Security update for samba
  • csaf_suse · SUSE-FU-2022:4496-1Feature update for SCA patterns
  • csaf_redhat · RHBA-2021:1503Red Hat Bug Fix Advisory: samba bug fix update
  • csaf_opensuse · openSUSE-SU-2020:1513-1Security update for samba
  • csaf_redhat · RHSA-2020:5439Red Hat Security Advisory: samba security and bug fix update
  • csaf_suse · SUSE-SU-2020:2720-1Security update for samba
Recommended actionPatch now

CISA confirms exploitation in the wild and lists 2022-05-03 as the remediation due date.

Patch available
01

What, why and how

Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller. An attacker who successfully exploits the vulnerability could run a specially crafted application on a device on the network. The vulnerability is also known under the moniker of Zerologon.

What

Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller. An attacker who successfully exploits the vulnerability could run a specially crafted application on a device on the network. The vulnerability is also known under the moniker of Zerologon.

Why

The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.

How

An attacker operating through local access may attempt exploitation with low privileges. If successful, the issue may gain additional privileges.

What

Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller. An attacker who successfully exploits the vulnerability could run a specially crafted application on a device on the network. The vulnerability is also known under the moniker of Zerologon.

Why

The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.

How

An attacker operating through local access may attempt exploitation with low privileges. If successful, the issue may gain additional privileges.

02

Exploit reality and attack path

CVSS severity, EPSS forecast probability, public exploit material and CISA-confirmed exploitation are separate signals.

Observed exploitation
?Confirmed exploitation and public exploit material are separate signals. Attacks can occur without public proof-of-concept or exploit code.
Confirmed in the wild

CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2021-11-03. Known ransomware campaign use is recorded.

Public PoC / exploit material
?Confirmed exploitation and public exploit material are separate signals. Attacks can occur without public proof-of-concept or exploit code.
Reference recorded

A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.

Likely attack path
local access → Use of Insufficiently Random Values → gain additional privileges
Attack surface
Local
Privileges required
Low: a basic authenticated account is required
User interaction
None
Attack complexity
Low: no specialised conditions are recorded
Security boundary
Unchanged: impact remains within the vulnerable component's security authority
Weakness
?CWE means Common Weakness Enumeration: a standard category for the underlying weakness.
CWE-330 ↗

CWE-330: Use of Insufficiently Random Values. The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.

CVSS vector
?CVSS means Common Vulnerability Scoring System. The vector records the metric values used to calculate technical severity.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C

Common Vulnerability Scoring System 3.1: the compact vector below is decoded into plain language.

AVLocalAttack vector: The attacker needs local access to the vulnerable system.ACLowAttack complexity: No specialised conditions are required beyond attacker-controlled input.PRLowPrivileges required: The attacker needs basic user-level privileges.UINoneUser interaction: No action by another user is required.SUnchangedScope: The security impact remains within the vulnerable component's authority.CHighConfidentiality impact: A successful attack can cause a major loss.INoneIntegrity impact: No direct loss is represented by this metric.ANoneAvailability impact: No direct loss is represented by this metric.
Post-exploitation / living off the land
The issue can support a local privilege or sandbox boundary transition; normal system utilities may then be available in the gained context.
Privilege escalationCWE-330CISA KEVPublic exploit reference
A

Official authority intelligence

Only matched European and national findings are included. Language selectors and unavailable sources are omitted.

ENISA EUVD · EUVD-2020-12346Known-exploited evidence recorded

An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run a specially crafted application on a device on the network. To exploit the vulnerability, an unauthenticated attacker would be required to use MS-NRPC to connect to a domain controller to obtain domain administrator access. Microsoft is addressing the vulnerability in a phased two-part rollout. These updates address the vulnerability by modifying how Netlogon handles the usage of Netlogon secure channels. For guidelines on how to manage the changes required for this vulnerability and more information on the phased rollout, see How to manage the changes in Netlogon secure channel connections associated with CVE-2020-1472 (updated September 28, 2020). When the second phase of Windows updates become available in Q1 2021, customers will be notified via a revision to this security vulnerability. If you wish to be notified when these updates are released, we recommend that you register for the security notifications mailer to be alerted of content changes to this advisory. See Microsoft Technical Security Notifications.

Official EUVD record ↗
Canadian Centre for Cyber Security · English · AV21-073Microsoft security advisory – February 2021 monthly rollup

On 9 February 2021 Microsoft published Security Updates to address vulnerabilities in multiple products. Included were critical updates for the following: Included in this update is the default enablement of Domain Controller enforcement mode, which blocks insecure NRPC connections from non-compliant devices.  This update also addresses a vulnerability in Windows Win32k which may result in an escalation of privilege resulting in full system compromise. Microsoft has confirmed this vulnerability has been detected in the wild.

Official advisory ↗
Canadian Centre for Cyber Security · English · AL20-025Continued Exploitation by APT Actors of Multiple Vulnerabilities

On 20 October 2020 the National Security Agency (NSA) published a Cyber Security Advisory (U/OO/179811-20) [ 1 ] detailing recent malicious activity targeting US information systems. The Cyber Centre is aware that many Canadian entities operate similar information systems in Canada. These information systems and the networks linking them are critical components in today’s interconnected world. Relied upon by governments, utilities, small businesses and individuals worldwide, they require regular updates to secure them from malicious activity that targets known or recently discovered vulnerabilities. While manufacturers work hard to provide updates for vulnerabilities, these updates are not always applied in a timely manner by consumers. The Cyber Centre continues to receive reports [ 2 ] [ 5 ] [ 6 ] of persistent exploitation of known vulnerabilities. Much of the reported activity appears to be the result of well-coordinated Advanced Persistent Threat (APT) actors targeting systems such as unpatched remote access services, security appliances and application servers. The Cyber Centre recommends that individuals and corporations review the following security guidance to better protect their information systems: Cyber Centre Publications [ 3 ] Top 10 IT Security Actions to Protect Internet Connected Networks and Information (ITSM.10.189) [ 4 ] NSA report U/OO/179811-20 [ 1 ] - A comprehensive list of vulnerabilities impacting information systems as well as general and tailored recommendations. Should organizations identify similar activity to that described in the referenced Advisories and Alerts, recipients are encouraged to contact the Cyber Centre by email ( contact@cyber.gc.ca ) or by telephone ( 1-833-CYBER-88 or 1-833-292-3788 ).

Official advisory ↗
Canadian Centre for Cyber Security · English · AL20-022Microsoft Netlogon Elevation of Privilege Vulnerability - CVE-2020-1472 - update 1

The Cyber Centre has become aware of recently published proofs of concept exploit code related to CVE-2020-1472, a Netlogon elevation of privilege vulnerability. The Cyber Centre strongly recommends that organizations immediately patch vulnerable systems.

Official advisory ↗
Cyber Security Agency of Singapore · English · CSA-SB-20200819Security Bulletin 19 Aug 2020

The Cyber Security Agency of Singapore included this CVE in its official Security Bulletin 19 Aug 2020, published on 19 August 2020. Open the linked bulletin for the product, severity and reference information published in that issue.

Official advisory ↗
CERT-FR · French · CERTFR-2021-AVI-772Multiples vulnérabilités dans les produits Schneider

e.org/CVERecord?id=CVE-2019-11135 Référence CVE CVE-2020-0601 https://www.cve.org/CVERecord?id=CVE-2020-0601 Référence CVE CVE-2020-0609 https://www.cve.org/CVERecord?id=CVE-2020-0609 Référence CVE CVE-2020-0610 https://www.cve.org/CVERecord?id=CVE-2020-0610 Référence CVE CVE-2020-0796 https://www.cve.org/CVERecord?id=CVE-2020-0796 Référence CVE CVE-2020-0938 https://www.cve.org/CVERecord?id=CVE-2020-0938 Référence CVE CVE-2020-1020 https://www.cve.org/CVERecord?id=CVE-2020-1020 Référence CVE CVE-2020-1350 https://www.cve.org/CVERecord?id=CVE-2020-1350 Référence CVE CVE-2020-13987 https://www.cve.org/CVERecord?id=CVE-2020-13987 Référence CVE CVE-2020-1472 https://www.cve.org/CVERecord?id=CVE-2020-1472 Référence CVE CVE-2020-17438 https://www.cve.org/CVERecord?id=CVE-2020-17438 Référence CVE CVE-2021-22800 https://www.cve.org/CVERecord?id=CVE-2021-22800 Référence CVE CVE-2021-22801 https://www.cve.org/CVERecord?id=CVE-2021-22801 Référence CVE CVE-2021-22802 https://www.cve.org/CVERecord?id=CVE-2021-22802 Référence CVE CVE-2021-22803 https://www.cve.org/CVERecord?id=CVE-2021-22803 Référence CVE CVE-2021-22804 https://www.cve.org/CVERecord?id=CVE-2021-22804 Référence CVE CVE-2021-22805 https://www.cve.org/CVERecord?id=CVE-2021-22805 Référence CVE CVE-2021-22806 https://www.cve.org/CVERecord?id=C

Official advisory ↗
CERT-FR · French · CERTFR-2021-AVI-638Multiples vulnérabilités dans Juniper Junos Space

d?id=CVE-2020-10029 Référence CVE CVE-2020-10543 https://www.cve.org/CVERecord?id=CVE-2020-10543 Référence CVE CVE-2020-10878 https://www.cve.org/CVERecord?id=CVE-2020-10878 Référence CVE CVE-2020-12723 https://www.cve.org/CVERecord?id=CVE-2020-12723 Référence CVE CVE-2020-13765 https://www.cve.org/CVERecord?id=CVE-2020-13765 Référence CVE CVE-2020-14318 https://www.cve.org/CVERecord?id=CVE-2020-14318 Référence CVE CVE-2020-14323 https://www.cve.org/CVERecord?id=CVE-2020-14323 Référence CVE CVE-2020-14351 https://www.cve.org/CVERecord?id=CVE-2020-14351 Référence CVE CVE-2020-14364 https://www.cve.org/CVERecord?id=CVE-2020-14364 Référence CVE CVE-2020-1472 https://www.cve.org/CVERecord?id=CVE-2020-1472 Référence CVE CVE-2020-15862 https://www.cve.org/CVERecord?id=CVE-2020-15862 Référence CVE CVE-2020-16092 https://www.cve.org/CVERecord?id=CVE-2020-16092 Référence CVE CVE-2020-1971 https://www.cve.org/CVERecord?id=CVE-2020-1971 Référence CVE CVE-2020-1983 https://www.cve.org/CVERecord?id=CVE-2020-1983 Référence CVE CVE-2020-25211 https://www.cve.org/CVERecord?id=CVE-2020-25211 Référence CVE CVE-2020-25645 https://www.cve.org/CVERecord?id=CVE-2020-25645 Référence CVE CVE-2020-25656 https://www.cve.org/CVERecord?id=CVE-2020-25656 Référence CVE CVE-2020-25705 https://www.cve.org/CVERecord?id=CVE-2

Official advisory ↗
CERT-FR · French · CERTFR-2021-AVI-589Multiples vulnérabilités dans Juniper Junos Space Log Collector

d?id=CVE-2020-12243 Référence CVE CVE-2020-12321 https://www.cve.org/CVERecord?id=CVE-2020-12321 Référence CVE CVE-2020-12351 https://www.cve.org/CVERecord?id=CVE-2020-12351 Référence CVE CVE-2020-12723 https://www.cve.org/CVERecord?id=CVE-2020-12723 Référence CVE CVE-2020-12825 https://www.cve.org/CVERecord?id=CVE-2020-12825 Référence CVE CVE-2020-14305 https://www.cve.org/CVERecord?id=CVE-2020-14305 Référence CVE CVE-2020-14331 https://www.cve.org/CVERecord?id=CVE-2020-14331 Référence CVE CVE-2020-14372 https://www.cve.org/CVERecord?id=CVE-2020-14372 Référence CVE CVE-2020-14385 https://www.cve.org/CVERecord?id=CVE-2020-14385 Référence CVE CVE-2020-1472 https://www.cve.org/CVERecord?id=CVE-2020-1472 Référence CVE CVE-2020-15862 https://www.cve.org/CVERecord?id=CVE-2020-15862 Référence CVE CVE-2020-25632 https://www.cve.org/CVERecord?id=CVE-2020-25632 Référence CVE CVE-2020-25643 https://www.cve.org/CVERecord?id=CVE-2020-25643 Référence CVE CVE-2020-25647 https://www.cve.org/CVERecord?id=CVE-2020-25647 Référence CVE CVE-2020-25705 https://www.cve.org/CVERecord?id=CVE-2020-25705 Référence CVE CVE-2020-27749 https://www.cve.org/CVERecord?id=CVE-2020-27749 Référence CVE CVE-2020-27779 https://www.cve.org/CVERecord?id=CVE-2020-27779 Référence CVE CVE-2020-28374 https://www.cve.org/CVERecord?id=C

Official advisory ↗
CERT-FR · French · CERTFR-2021-AVI-299Multiples vulnérabilités dans Oracle Systems

De multiples vulnérabilités ont été découvertes dans Oracle Systems. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une atteinte à l'intégrité des données et une atteinte à la confidentialité des données.

Official advisory ↗
CERT-FR · French · CERTFR-2020-AVI-579Vulnérabilité dans Samba

Une vulnérabilité a été découverte dans le logiciel Samba. Elle permet à un attaquant de provoquer une élévation de privilèges si le serveur Samba est configuré pour être contrôleur de domaine (de type 'NT4' ou Active Directory). La configuration par défaut de Samba v4.8 (et ultérieures) permet de se prémunir contre cette vulnérabilité.

Official advisory ↗
CERT-FR · French · CERTFR-2020-AVI-501Multiples vulnérabilités dans Microsoft Windows

.cve.org/CVERecord?id=CVE-2020-1378 Référence CVE CVE-2020-1379 https://www.cve.org/CVERecord?id=CVE-2020-1379 Référence CVE CVE-2020-1383 https://www.cve.org/CVERecord?id=CVE-2020-1383 Référence CVE CVE-2020-1417 https://www.cve.org/CVERecord?id=CVE-2020-1417 Référence CVE CVE-2020-1459 https://www.cve.org/CVERecord?id=CVE-2020-1459 Référence CVE CVE-2020-1464 https://www.cve.org/CVERecord?id=CVE-2020-1464 Référence CVE CVE-2020-1466 https://www.cve.org/CVERecord?id=CVE-2020-1466 Référence CVE CVE-2020-1467 https://www.cve.org/CVERecord?id=CVE-2020-1467 Référence CVE CVE-2020-1470 https://www.cve.org/CVERecord?id=CVE-2020-1470 Référence CVE CVE-2020-1472 https://www.cve.org/CVERecord?id=CVE-2020-1472 Référence CVE CVE-2020-1473 https://www.cve.org/CVERecord?id=CVE-2020-1473 Référence CVE CVE-2020-1474 https://www.cve.org/CVERecord?id=CVE-2020-1474 Référence CVE CVE-2020-1475 https://www.cve.org/CVERecord?id=CVE-2020-1475 Référence CVE CVE-2020-1477 https://www.cve.org/CVERecord?id=CVE-2020-1477 Référence CVE CVE-2020-1478 https://www.cve.org/CVERecord?id=CVE-2020-1478 Référence CVE CVE-2020-1479 https://www.cve.org/CVERecord?id=CVE-2020-1479 Référence CVE CVE-2020-1480 https://www.cve.org/CVERecord?id=CVE-2020-1480 Référence CVE CVE-2020-1484 https://www.cve.org/CVERecord?id=CVE-2020-1484 Ré

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2020-008530複数の Microsoft Windows 製品における権限昇格の脆弱性

複数の Microsoft Windows 製品には、権限を昇格される脆弱性が存在します。 ベンダは、本脆弱性を「Netlogon の特権の昇格の脆弱性」として公開しています。

Official advisory ↗
KISA KrCERT/CC · Korean · KNVD-5271MS 2월 보안 위협에 따른 정기 보안 업데이트 권고

원격 코드 실행 취약성 Microsoft Office Excel CVE-2021-24067 Microsoft Excel 원격 코드 실행 취약성 Microsoft Office SharePoint CVE-2021-24072 Microsoft SharePoint Server 원격 코드 실행 취약성 Microsoft Office SharePoint CVE-2021-24071 Microsoft SharePoint 정보 유출 취약성 Microsoft Office SharePoint CVE-2021-24066 Microsoft SharePoint 원격 코드 실행 취약성 Microsoft Office SharePoint CVE-2021-1726 Microsoft SharePoint 스푸핑 취약성 Microsoft Teams CVE-2021-24114 Microsoft Teams iOS Information Disclosure Vulnerability Microsoft Windows Codecs Library CVE-2021-24091 Windows 카메라 코덱 팩 원격 코드 실행 취약성 Microsoft Windows Codecs Library CVE-2021-24081 Microsoft Windows 코덱 라이브러리 원격 코드 실행 취약성 Netlogon CVE-2020-1472 NetLogon 권한 상승 취약성 Role: DNS Server CVE-2021-24078 Windows DNS 서버 원격 코드 실행 취약성 Role: Hyper-V CVE-2021-24076 Microsoft Windows VMSwitch 정보 유출 취약성 Role: Windows Fax Service CVE-2021-24077 Windows Fax 서비스 원격 코드 실행 취약성 Role: Windows Fax Service CVE-2021-1722 Windows Fax 서비스 원격 코드 실행 취약성 Skype for Business CVE-2021-24099 비즈니스용 Skype 서비스 거부 취약성 Skype for Business CVE-2021-24073 비즈니스용 Skype 및 Lync 스푸핑 취약성 SysInternals CVE-2021-1733 Sysinternals PsExec 권한 상승 취약성 System Center CVE-2021-1728 System Center Operations Manager 권한 상승 취약성 Visual Studio CVE-2021-1639 Visual Studio Code 원격 코드 실행 취약성 Visual Studio Code CVE-2021-26700 Visual Studio Code npm-sc

Official advisory ↗
KISA KrCERT/CC · Korean · KNVD-5251주요 보안 취약점 업데이트를 재확인 하세요!!

재확인 하세요!! 2021.01.05 ##### □ 개요 o `20년 보안공지 된 취약점 중 업데이트 적용에 대한 재확인이 필요한 주요 취약점 리스트 ※ 미국 NSA 발표, 랜섬웨어 유포에 악용된 취약점 등 이슈화 된 취약점 선정 ##### □ 주요 내용 No 구분 CVE번호 제조사 제품명 취약점 종류 패치정보 및 보안공지 1 네트워크 CVE-2019-15978 외 10개 Cisco Data Center Network Manager 명령어 삽입 취약점 등 [1] 2 네트워크 CVE-2019-19781 Citrix ADC, Gateway,SDWAN-WANOP 임의코드 실행 취약점 [2] 3 네트워크 CVE-2020-11896 Cisco ASR 500,5500 원격코드 실행 취약점 [3] 4 운영체제 CVE-2020-7247 - OpenSMTPD 원격코드 실행 취약점 [4] 5 운영체제 CVE-2020-0674 MS 인터넷 익스플로러 원격코드 실행 취약점 [5] 6 운영체제 CVE-2020-0688 MS 윈도우 Exchange 서버 원격코드 실행 취약점 [6] 7 운영체제 CVE-2020-0796 MS 윈도우 SMBv3 원격코드 실행 취약점 [7] 8 운영체제 CVE-2019-14287 유닉스/리눅스 - sudo 명령어 취약점 [8] 9 운영체제 CVE-2020-1472 MS 윈도우 서버 Netlogon 권한상승 취약점 [9] 10 가상화 CVE-2020-3943 외 2개 VMware vRealize Operations 임의코드 실행 취약점 등 [10] 11 가상화 CVE-2020-3952 VMware vCenter Server 정보유노출 취약점 [11] 12 웹서버 CVE-2020-1938 Apache Tomcat 원격코드 실행 취약점 [12] 13 보안솔루션 CVE-2020-7845 지란지교시큐리티 스팸스나이퍼 버퍼오버플로우 취약점 [13] 14 보안솔루션 CVE-2020-25043 외 11개 Kaspersky 등 7개사 백신프로그램 임의파일 삭제 취약점 등 [14] 15 원격협업 CVE-2020-6109 외 1개 Zoom Zoom 임의파일 쓰기 취약점 [15] 16 원격협업 CVE-2020-8207 Citrix Workspace 권한 상승 취약점 [16] 17 원격협업 CVE-2020-13699 Team Viewer TeamViewer 원격코드 실행 취약점 [17] 18 IoT CVE-2020-10173 외 10개 LG 등 9개사 공유기, IP카메라 등 악성코드 유포, DDoS [18] 19 복합기 CVE-2018-5924 HP HP DesignJet 원격코드 실행 취약점 [19] 20 솔루션 CVE-20

Official advisory ↗
KISA KrCERT/CC · Korean · KNVD-5212MS 윈도우 서버 Netlogon 취약점 보안 업데이트 권고 (2차)

CVE-2020-1472 윈도우 서버의 Netlogon 권한상승 취약점(CVE-2020-1472)에 대한 최신 업데이트가 적용되어 있지 않은 경우 공격 위험에 노출

Official advisory ↗
KISA KrCERT/CC · Korean · KNVD-5219해킹 공격에 악용되는 취약점 업데이트 권고

#### 해킹 공격에 악용되는 취약점 업데이트 권고 2020.10.22 ##### □ 개요 o 美 국가안보국(NSA), 해커들이 사이버 공격에 악용하는 25개의 취약점 리스트 발표 [1] o 공격자는 해당 취약점을 악용하여 침해사고를 발생시킬 수 있으므로, 기업 담당자 및 해당 시스템을 이용중인 사용자는 최신 버전으로 업데이트 권고 ##### □ 주요 내용 제조사 제품 CVE ID 내용 Microsoft 윈도우즈 CVE-2019-0708 [2] 공격자가 특별하게 조작된 RDP 패킷을 전송하여 피해 시스템에 임의 코드를 실행할 수 있는 취약점 CVE-2020-1040 [3] 공격자가 NTLM MIC(메시지 무결성 검증)을 우회하여 중간자공격(MITM)이 가능한 취약점 CVE-2020-0601 [4] 암호화 인증서를 검증하는 API에서 발생하는 중간자공격(MITM)이 가능한 취약점 CVE-2019-0803 [5] 메모리의 객체 처리가 미흡하여 발생하는 권한상승 취약점 CVE-2020-1472 [6] Netlogon 프로토콜의 취약한 암호화 운영모드 사용으로 발생하는 권한상승 취약점 윈도우 서버 CVE-2020-1350 [7] DNS로 운영되는 Windows 서버에서 요청값에 대한 처리가 미흡하여 발생하는 원격코드실행 취약점 윈도우 Exchange 서버 CVE-2020-0688 [8] 메모리의 객체에 대한 처리가 미흡하여 발생하는 원격코드실행 취약점 Oracle WebLogic Server CVE-2015-4852 [9] 조작된 자바 객체를 역직렬화하여 발생하는 임의코드실행 취약점 Coherence CVE-2020-2555 [10] 조작한 T3 프로토콜의 request를 허용 및 역직렬화하여 발생하는 원격코드실행 취약점 Citrix ADC, Gateway, SDWAN- WANOP CVE-2019-19781 [11] 공격자가 인증을 우회하여 임의코드를 실행할 수 있는 취약점 CVE-2020-8193, 8195, 8196 [12] 허가되지 않은 사용자가 특정 URL에접근 가능하여 발생하는 정보노출 취약점 Atlassian Confluence Server CVE-2019-3396 [13] Widget Connector macro에서 발생하는 경로탐색 및 원격코드실행 취약점 Crowd, Crowd Data Center CVE-2019-115

Official advisory ↗
KISA KrCERT/CC · Korean · KNVD-5198Samba 취약점 보안 업데이트 권고

Samba AD(Active Directory) DC(Domain Controller)에서 Netlogon 프로토콜의 취약한 암호화 운영모드 사용으로 발생하는 권한상승 취약점(CVE-2020-1472) [2]

Official advisory ↗
KISA KrCERT/CC · Korean · KNVD-5195MS 윈도우 서버 Netlogon 취약점 보안 업데이트 권고 (1차)

윈도우 서버의 Netlogon에서 취약한 암호화 운영모드를 사용하여 발생하는 권한상승 취약점(CVE-2020-1472) [2]

Official advisory ↗
KISA KrCERT/CC · Korean · KNVD-5191MS 8월 보안 위협에 따른 정기 보안 업데이트 권고

영향 : 원격코드실행 o 중요도 : 긴급 o 관련 KB번호 - 4565349, 4565351, 4566782, 4571692, 4571694, 4571709, 4571741 ##### □ 해결책 o 영향 받는 소프트웨어를 이용하는 경우 마이크로소프트사의 보안 패치 적용 2. Windows Server 2019, Windows Server 2016, Server Core 설치(2019, 2016, v1909, v1903, v1803) 보안 업데이트 ##### □ 설명 o 공격자가 특수하게 제작된 악성 응용 프로그램을 실행할 경우, 원격코드실행을 허용하는 취약점 o 관련취약점 : - 원격코드실행 취약점(CVE-2020-1339, CVE-2020-1379, CVE-2020-1473, CVE-2020-1477, CVE-2020-1478, CVE-2020-1492, CVE-2020-1520, CVE-2020-1525, CVE-2020-1554, CVE-2020-1557, CVE-2020-1558, CVE-2020-1561, CVE-2020-1562, CVE-2020-1564) - 권한상승 취약점(CVE-2020-1337, CVE-2020-1377, CVE-2020-1378, CVE-2020-1417, CVE-2020-1467, CVE-2020-1470, CVE-2020-1472, CVE-2020-1475, CVE-2020-1479, CVE-2020-1480, CVE-2020-1484, CVE-2020-1486, CVE-2020-1488, CVE-2020-1489, CVE-2020-1490, CVE-2020-1509, CVE-2020-1511, CVE-2020-1513, CVE-2020-1515, CVE-2020-1516, CVE-2020-1517, CVE-2020-1518, CVE-2020-1519, CVE-2020-1521, CVE-2020-1522, CVE-2020-1524, CVE-2020-1526, CVE-2020-1527, CVE-2020-1528, CVE-2020-1529, CVE-2020-1530, CVE-2020-1531, CVE-2020-1533, CVE-2020-1534, CVE-2020-1537, CVE-2020-1538, CVE-2020-1549, CVE-2020-1550, CVE-2020-1552, CVE-2020-1553, CVE-2020-1556, CVE-2020-1565, CVE-2020-1566, CVE-2020-1579, CVE-2020-1584, CVE-2020-1587) - 서비스거부 취약점(CVE-2020-1466) - 스푸핑 취약점(CVE-2020-1464) - 정보노출 취약점(

Official advisory ↗
03

Patch and workaround

Operational remediation based on structured source evidence.

Status
?Patch availability is based on structured fixed-version fields and authoritative update references. If no fix is verified, check the vendor advisory before making a change.
Patch available
Affected
Fixed
Schneider Electric Microsoft Windows 10
Action
Version Windows 10 of the Microsoft Windows includes a fix for this vulnerability and is available for download here: • https://www.microsoft.com/en-in/software-download/windows10 • Reboot is required
Workaround
No verified workaround is recorded. Limit untrusted access and use least privilege until authoritative guidance is available.
04

Evidence and provenance

Published 17 Aug 2020 · Last source change 21 Oct 2025, 23:35 UTC · CWE-330 · Use of Insufficiently Random Values

CVE recordCVE.org · 5.1
CVSS sourceCNA
EPSS source
?The date BlackTree first stored a score for this CVE from the daily FIRST EPSS feed.
FIRST · tracked since 2026-08-14
European sourceENISA EUVD · EUVD-2020-12346
Product sourceVendor CSAF · Schneider Electric CPCERT
Remediation sourceVendor CSAF · Schneider Electric CPCERT
CWE sourceCISA KEV
NVD statusNVD enriched

Core structured fields are present and their contributing authorities are shown above.

Material change intelligence

What changed after publication

View recent updates ↗
  1. Vendor guidanceAuthoritative vendor guidance changed: added remediation: portal.msrc.microsoft.com/CVE-2020-1472; removed remediation: download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-285-05&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2021-285-05_Conext_Advisor_and_Conext_Control_Security_Notification.pdf.
    Before
    patch: oracle.com/cpuApr2021.html · patch: portal.msrc.microsoft.com/CVE-2020-1472 · remediation: download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-285-05&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2021-285-05_Conext_Advisor_and_Conext_Control_Security_Notification.pdf
    After
    patch: oracle.com/cpuApr2021.html · patch: portal.msrc.microsoft.com/CVE-2020-1472 · remediation: portal.msrc.microsoft.com/CVE-2020-1472
    portal.msrc.microsoft.com ↗
  2. Affected versionsThe structured affected or fixed version information changed.
    Before
    Windows Server version 2004: 10.0.0 < publication; Windows Server 2019: 10.0.0 < publication; Windows Server 2019 (Server Core installation): 10.0.0 < publication; Windows Server, version 1909 (Server Core installation): 10.0.0 < publication; Windows Server, version 1903 (Server Core installation): 10.0.0 < publication; Windows Server 2016: 10.0.0 < publication; Windows Server 2016 (Server Core installation): 10.0.0 < publication; Windows Server 2008 R2 Service Pack 1: 6.1.0 < publication; Windows Server 2008 R2 Service Pack 1 (Server Core installation): 6.0.0 < publication; Windows Server 2012: 6.2.0 < publication; Windows Server 2012 (Server Core installation): 6.2.0 < publication; Windows Server 2012 R2: 6.3.0 < publication; Windows Server 2012 R2 (Server Core installation): 6.3.0 < publication; Windows Server version 20H2: 10.0.0 < publication · Fixed: Version Windows 10 of the Microsoft Windows includes a fix for this vulnerability and is available for download here: • https://www.microsoft.com/en-in/software-download/windows10 • Reboot is required
    After
    Windows Server version 2004: 10.0.0 < publication; Windows Server 2019: 10.0.0 < publication; Windows Server 2019 (Server Core installation): 10.0.0 < publication; Windows Server, version 1909 (Server Core installation): 10.0.0 < publication; Windows Server, version 1903 (Server Core installation): 10.0.0 < publication; Windows Server 2016: 10.0.0 < publication; Windows Server 2016 (Server Core installation): 10.0.0 < publication; Windows Server 2008 R2 Service Pack 1: 6.1.0 < publication; Windows Server 2008 R2 Service Pack 1 (Server Core installation): 6.0.0 < publication; Windows Server 2012: 6.2.0 < publication; Windows Server 2012 (Server Core installation): 6.2.0 < publication; Windows Server 2012 R2: 6.3.0 < publication; Windows Server 2012 R2 (Server Core installation): 6.3.0 < publication; Windows Server version 20H2: 10.0.0 < publication · Fixed: An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
    CISA KEV ↗
  3. Affected versionsThe structured affected or fixed version information changed.
    Before
    10.0.0 < publication; 6.1.0 < publication · Fixed: An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
    After
    Windows Server version 2004: 10.0.0 < publication; Windows Server 2019: 10.0.0 < publication; Windows Server 2019 (Server Core installation): 10.0.0 < publication; Windows Server, version 1909 (Server Core installation): 10.0.0 < publication; Windows Server, version 1903 (Server Core installation): 10.0.0 < publication; Windows Server 2016: 10.0.0 < publication; Windows Server 2016 (Server Core installation): 10.0.0 < publication; Windows Server 2008 R2 Service Pack 1: 6.1.0 < publication; Windows Server 2008 R2 Service Pack 1 (Server Core installation): 6.0.0 < publication; Windows Server 2012: 6.2.0 < publication; Windows Server 2012 (Server Core installation): 6.2.0 < publication; Windows Server 2012 R2: 6.3.0 < publication; Windows Server 2012 R2 (Server Core installation): 6.3.0 < publication; Windows Server version 20H2: 10.0.0 < publication · Fixed: An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
    CNA ↗
  4. Affected versionsThe structured affected or fixed version information changed.
    Before
    Windows Server version 2004: 10.0.0 < publication; Windows Server 2019: 10.0.0 < publication; Windows Server 2019 (Server Core installation): 10.0.0 < publication; Windows Server, version 1909 (Server Core installation): 10.0.0 < publication; Windows Server, version 1903 (Server Core installation): 10.0.0 < publication; Windows Server 2016: 10.0.0 < publication; Windows Server 2016 (Server Core installation): 10.0.0 < publication; Windows Server 2008 R2 Service Pack 1: 6.1.0 < publication; Windows Server 2008 R2 Service Pack 1 (Server Core installation): 6.0.0 < publication; Windows Server 2012: 6.2.0 < publication; Windows Server 2012 (Server Core installation): 6.2.0 < publication; Windows Server 2012 R2: 6.3.0 < publication; Windows Server 2012 R2 (Server Core installation): 6.3.0 < publication; Windows Server version 20H2: 10.0.0 < publication · Fixed: An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
    After
    Windows Server version 2004: 10.0.0 < publication; Windows Server 2019: 10.0.0 < publication; Windows Server 2019 (Server Core installation): 10.0.0 < publication; Windows Server, version 1909 (Server Core installation): 10.0.0 < publication; Windows Server, version 1903 (Server Core installation): 10.0.0 < publication; Windows Server 2016: 10.0.0 < publication; Windows Server 2016 (Server Core installation): 10.0.0 < publication; Windows Server 2008 R2 Service Pack 1: 6.1.0 < publication; Windows Server 2008 R2 Service Pack 1 (Server Core installation): 6.0.0 < publication; Windows Server 2012: 6.2.0 < publication; Windows Server 2012 (Server Core installation): 6.2.0 < publication; Windows Server 2012 R2: 6.3.0 < publication; Windows Server 2012 R2 (Server Core installation): 6.3.0 < publication; Windows Server version 20H2: 10.0.0 < publication · Fixed: Version Windows 10 of the Microsoft Windows includes a fix for this vulnerability and is available for download here: • https://www.microsoft.com/en-in/software-download/windows10 • Reboot is required
    Schneider Electric CPCERT ↗
Material fields only · duplicate refreshes suppressed · history retained for the configured operational retention period
Technical terms and abbreviations used in this report
CVE
Common Vulnerabilities and Exposures: the public identifier for one disclosed vulnerability.
CVSS
Common Vulnerability Scoring System: a technical severity framework; it is not patching priority by itself.
EPSS
Exploit Prediction Scoring System: FIRST's estimate of the probability that exploitation activity will be observed in the next 30 days; it is a forecast, not confirmation.
CWE
Common Weakness Enumeration: the standard category describing the underlying software or hardware weakness.
CNA
CVE Numbering Authority: an organisation authorised to assign and publish CVE records.
CISA ADP
Cybersecurity and Infrastructure Security Agency Authorized Data Publisher: structured enrichment added to a CVE record.
NVD
National Vulnerability Database: NIST's enrichment service for CVE records.
CERT / CSIRT
A computer security incident response team that publishes warnings or coordinates incident response.
PoC
Proof of concept: public material that demonstrates or helps reproduce exploitation.
CSAF
Common Security Advisory Framework: a machine-readable format for security advisories.
LoTL
Living off the land: abuse of legitimate tools or system functions during an attack.
Free version - for non-commercial use only.CVE-2020-1472 · cve.blacktree.nl