Skip to main content

Netlogon elevation of privilege vulnerability (CVE-2020-1472)

The ACSC is aware of a recently disclosed critical vulnerability in Microsoft Active Directory Domain Controller systems that allows unauthenticated attackers to trivially access administrative credentials.

Alert status

Proof of concept code to exploit the vulnerability is now freely available online and has been integrated into common exploit frameworks and tools.

CVE-2020-1472 also affects several other products not previously covered by the advisory including, but not limited to:

  • Samba implementations on Linux systems prior to v4.8. This includes all Linux distributions that utilise the official Samba packages.

In most cases, CVE-2020-1472 is a privilege escalation vulnerability. However, adversaries may be able exploit the vulnerability for initial access if a Domain Controller is internet-exposed.

Content complexity
This rating relates to the complexity of the advice and information provided on the page.
Was this information helpful?
Was this information helpful?

Thanks for your feedback!


Tell us why this information was helpful and we’ll work on making more pages like it