ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

US CISA: Agencies Must Patch Zerologon Bug by Monday

criticalVulnerabilityimportance 60CVE-2020-1472

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-1472
Unauthenticated Privilege Escalation (Zerologon) in Microsoft Netlogon Domain Controllers

CVE-2020-1472, widely known as "Zerologon," is an elevation-of-privilege flaw in how the Netlogon secure channel is established over the Netlogon Remote Protocol (MS-NRPC) on Microsoft domain controllers. An unauthenticated attacker with network reachability to a domain controller sends specially crafted Netlogon messages to establish a vulnerable secure channel and then runs a specially crafted application on the network to obtain domain administrator access. Successful exploitation yields domain administrator privileges, effectively full compromise of the Active Directory environment, and the flaw is known to be used in ransomware operations. Any organization running affected Windows Server versions (2008 through 20H2) as domain controllers is exposed, along with environments using Netlogon implementations from Samba and distributions or products from Fedora, openSUSE, Canonical (Ubuntu), Debian, Synology, and Oracle. Exploitation is highly active: a public Zerologon PoC/exploit is available, the flaw is on CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03, with known ransomware use), and EPSS estimates a 99.4% probability of exploitation within 30 days.

Do: Apply the vendor updates on all domain controllers and other affected systems immediately, following Microsoft's two-phase Netlogon secure channel guidance (the enforcement phase of the phased rollout began in Q1 2021). Audit Netlogon secure-channel connections and event logs for clients still using vulnerable connections before enabling full enforcement, and install updated packages for Samba and other Netlogon implementations from Fedora, openSUSE, Ubuntu, Debian, Synology, and Oracle. Given known ransomware use, prioritize patching any domain controller reachable from user networks, VPNs, or the internet.

5.599% KEV ransomware PoC
  • Microsoft Windows Server (when acting as a domain controller)
  • Samba (Netlogon secure channel implementation)
  • Fedora Project Fedora Linux
  • +5 more
massmillions of domain controllers worldwide (essentially every Active Directory domain), with hundreds of thousands of domain controllers/RPC endpoints…
Full article304 words · extracted from infosecurity-magazine.com · click to collapse

The US Department of Homeland Security (DHS) has issued an emergency directive designed to force all civilian government agencies to patch a high-risk Windows vulnerability.

CVE-2020-1472 is a critical elevation of privilege bug which exists when an attacker uses the Netlogon Remote Protocol to establish a vulnerable secure channel connection to a domain controller, according to Microsoft. It affects Windows Server 2008 onwards.

Dubbed “Zerologon,” the flaw was fixed in the August Patch Tuesday, although proof-of-concept exploits started to appear over the past week.

As such, it now poses an “unacceptable risk” to the federal civilian executive branch that requires “immediate and urgent action,” the Cybersecurity and Infrastructure Security Agency (CISA) said on Friday.

“The vulnerability in Microsoft Windows Netlogon Remote Protocol (MS-NRPC), a core authentication component of Active Directory, could allow an unauthenticated attacker with network access to a domain controller to completely compromise all Active Directory identity services,” it explained.

“Applying the update released on August 11 to domain controllers is currently the only mitigation to this vulnerability (aside from removing affected domain controllers from the network).”

The resulting emergency directive 20-04 requires all civilian government agencies to patch all Windows Servers with a domain controller role by 23.59 EDT this evening, or remove them from the network.

ExtraHop CISO, Jeff Costlow, argued that the Zerologon bug is easy for attackers to exploit

“The first PoC’s have shown that unauthenticated attackers are able to obtain full administrator privileges on Active Directory systems,” he added.

“Any organizations without the ability to detect exploit attempts will remain at high risk if they delayed the patch as there is no way to know if they were exposed in between the time of reporting and the system update. We urge organizations to patch immediately and be aware that their system might have already been compromised.”

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/cisa-agencies-must-patch-zerologon/