CVE-2020-1472 “Zerologon” Critical Privilege Escalation: What You Need To Know

CVE-2020-1472

Earlier today, security firm Secura published a technical paper on CVE-2020-1472, a CVSS-10 privilege escalation vulnerability in Microsoft’s Netlogon authentication process that Secura christened “Zerologon.” The vulnerability, which was partially patched in Microsoft’s August 2020 Patch Tuesday release, arises from a flaw in the cryptographic implementation of the Netlogon protocol, specifically in its usage of AES-CFB8 encryption. The impact of successful exploitation is enormous: The flaw allows for full takeover of Active Directory domains by compromising Windows Servers running as domain controllers—in Secura’s words, enabling “an attacker with a foothold on your internal network to essentially become Domain Admin with one click. All that is required is for a connection to the Domain Controller to be possible from the attacker’s viewpoint.” This RPC connection can be made either directly or over SMB via namedpipes.

Secura’s blog includes proof-of-concept (PoC) code that performs the authentication bypass and is easily able to be weaponized for use in attacker operations, including ransomware and other malware propagation. It’s unlikely that it will take long for a fully weaponized exploit (or several) to hit the internet.

InsightVM customers can assess their exposure to CVE-2020-1472 with an authenticated check. Organizations that have not already applied Microsoft’s August 11, 2020 security updates are urged to consider patching CVE-2020-1472 on an emergency basis. Microsoft customers who have successfully applied the August 2020 security updates can deploy Domain Controller (DC) enforcement mode either now or after the Q1 2021 update that includes the second part of the patch for this vulnerability. Microsoft has guidance here on how to manage changes in Netlogon secure channel connections associated with this vulnerability.

For more Rapid7 analysis, further evaluation of Secura’s technical paper, and guidance, see Zerologon’s AttackerKB entry here.

Affected products

  • Windows Server 2008 R2 for x64-based Systems Service Pack 1
  • Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
  • Windows Server 2012
  • Windows Server 2012 (Server Core installation)
  • Windows Server 2012 R2
  • Windows Server 2012 R2 (Server Core installation)
  • Windows Server 2016
  • Windows Server 2016 (Server Core installation)
  • Windows Server 2019
  • Windows Server 2019 (Server Core installation)
  • Windows Server, version 1903 (Server Core installation)
  • Windows Server, version 1909 (Server Core installation)
  • Windows Server, version 2004 (Server Core installation)

References

  • https://attackerkb.com/topics/7FbcgDOidQ/cve-2020-1472?referrer=blog#rapid7-analysis
  • https://www.secura.com/pathtoimg.php?id=2055
  • https://www.zdnet.com/article/zerologon-attack-lets-hackers-take-over-enterprise-networks/
  • https://github.com/SecuraBV/CVE-2020-1472
  • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1472

If you like the site, please consider joining the telegram channel or supporting us on Patreon using the button below.

Patreon

Original Source