Microsoft last month fixed one of the most serious bugs ever reported to the company, an issue that could lead to a takeover of Windows Servers running as domain controllers on corporate networks.
The flaw was fixed on Patch Tuesday in August 2020 with the identifier CVE-2020-1472. It was described as an “elevation of privilege” in Netlogon (Netlogon is a Windows server process that authenticates users and other services on a domain).
The vulnerability received a maximum severity rating of 10, but the details were never made public, meaning users and IT admins didn't know how dangerous the problem was.

But in a blog post today, the team at Secura BV (a Dutch security company), published more details about this mysterious bug with a technical report describing CVE-2020-1472 in greater depth.
And according to the report, the bug is truly worthy of a 10/10 CVSSv3 severity rating.
According to Secura experts, the bug, which they named Zerologon, exploits a weak cryptographic algorithm used in the Netlogon authentication process.
This flaw allows an attacker to manipulate Netlogon authentication processes and:
- impersonates any computer on a network when attempting to authenticate against the domain controller
- disables security features in the Netlogon authentication process
- changes the password of a computer in the Active Directory domain controller
The gist, and the reason why the bug was named Zerologon, is that the attack is done by adding zero characters to certain Netlogon authentication parameters

The attack is very fast and can take up to three seconds at most. Furthermore, there are no limits to how an attacker can use the Zerologon attack. For example, the attacker could also impersonate the domain controller itself and change its password, allowing the attacker to take over the entire corporate network.
There are limitations to how a Zerologon attack can be used. It cannot be used to take over Windows servers from an external network. An attacker first needs to be already inside the network.
However, when this condition is met, it is literally game over for the company.
“This attack has a huge impact,” the Secura team said. “It essentially allows any attacker on the local network to completely compromise the Windows domain.”
Furthermore, this bug is also a boon for malware and ransomware gangs, which often rely on infecting a computer within a company's network to spread malware/ransomware to other computers. With Zerologon, this process has been greatly simplified.
