Microsoft has clarified the steps customers should take to ensure their devices are protected from ongoing attacks exploiting Windows Server Zerologon (CVE-2020-1472).
The company revised the advisory after customers were confused by Microsoft's initial guidance and were unsure whether applying the patch was enough to protect vulnerable Windows Server devices.

In a step-by-step approach, the updated advisory now explains the exact actions administrators should take to ensure their environments are protected and downtime is prevented in the event of an inbound attack designed to exploit servers that would otherwise be vulnerable to Zerologon exploits.
Microsoft has outlined the following plan for Windows administrators to follow when implementing the Netlogon Elevation of Privilege Vulnerability (CVE-2020-1472) security update that was released as part of the August 2020 update on Tuesday:
- UPDATE your Domain Controllers with an update released on August 11, 2020 or later.
- FIND which devices are making vulnerable connections by monitoring event logs.
- DETECT incompatible devices that make insecure connections.
- ENABLE enforcement mode to address CVE-2020-1472 in your environment.
The Zerologon vulnerability
CVE-2020-1472 is a critical security flaw – rated 10/10 – dubbed Zerologon by cybersecurity firm Secura and, when exploited, allows attackers to elevate privileges to a domain administrator.
This helps attackers take control of the domain, allowing them to change every user's password and execute any command they want.
As the security update issued by Microsoft in August may also cause some of the affected devices to experience authentication issues, Microsoft is releasing the Zerologon fix in two stages.
The first stage was released on August 11 as a security update that prevents Windows Active Directory Domain controllers from using insecure RPC communication.
It also logs authentication requests from non-Windows devices that do not use secure RPC channels to give administrators to fix the devices or replace them with ones that have support for secure RPC.
Starting on February 9, 2021, as part of this month's Patch Tuesday updates, Microsoft will release another update that will enable enforcement by requiring all devices on the network to use secure RPC unless explicitly allowed by administrators.
Ongoing Zerologon attacks
Last week, Microsoft warned administrators to urgently apply security updates for Zerologon after discovering that some attackers were using CVE-2020-1472 for their attacks.
Microsoft Threat Intelligence Analyst Kevin Beaumont confirmed that the attacks began on September 26, with attackers successfully exploiting a vulnerable Active Directory “server honeypot” using a Zerologon exploit over the internet.
