
Cloud Vulnerability DB
A community-led vulnerabilities database
The Netlogon Remote Protocol (MS-NRPC) vulnerability, tracked as CVE-2020-1472, is a critical security issue that affects domain controllers running Windows Server. This vulnerability was disclosed in August 2020 and addressed through a phased rollout approach. The vulnerability exists in the way the Netlogon secure channel connections are handled between domain-joined devices and Active Directory domain controllers (Microsoft Support).
The vulnerability affects the Netlogon Remote Protocol, which is an RPC interface used exclusively by domain-joined devices. The security update addresses the vulnerability by enforcing secure RPC usage for Netlogon secure channel connections between member computers and Active Directory domain controllers. The fix was implemented in two phases: the initial deployment phase starting August 11, 2020, which enabled protection for Windows devices by default, and the enforcement phase beginning February 9, 2021, which required all Windows and non-Windows devices to use secure RPC with Netlogon secure channel (Microsoft Support).
An unauthenticated, remote attacker could exploit this vulnerability by spoofing a client credential to establish a secure channel to a domain controller using the Netlogon remote protocol. The attacker could then use this access to change the computer's Active Directory password and escalate privileges to domain admin level (Microsoft Q&A).
The vulnerability is considered highly exploitable, particularly affecting domain controllers. All domain controllers in a forest must be updated to provide AD forest protection, including read-only domain controllers (RODCs). Windows Server 2008 SP2 is not vulnerable to this specific CVE because it does not use AES for Secure RPC (Microsoft Support).
Microsoft provided a comprehensive mitigation strategy involving a two-phase approach. Phase 1 (August 11, 2020) included deploying updates to all domain controllers, monitoring for warning events, and addressing non-compliant devices. Phase 2 (February 9, 2021) enforced secure RPC usage for all devices. Organizations can temporarily allow vulnerable connections through the 'Domain controller: Allow vulnerable Netlogon secure channel connections' group policy for non-compliant devices, though this is not recommended for long-term use (Microsoft Support).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."