CVE-2020-1472: Microsoft Netlogon Privilege Escalation Vulnerability.

Microsoft Netlogon Privilege Escalation Vulnerability. Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller. An attacker who successfully exploits the vulnerability could run a specially crafted application on a device on the network. The vulnerability is also known under the moniker of Zerologon.

Detection rules

Related briefings

Linked threat actors

Browse the CVE database

Read the full analysis on IntelFusions