Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - What You Need To Know About Zerologon
Articles

What You Need To Know About Zerologon

ISBuzz TeamBy ISBuzz TeamSeptember 30, 2020Updated:May 2, 20255 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Windows Encryption Keys Could Expose Users to Hackers
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Microsoft released an update for CVE-2020-1472 (now known as Zerologon) on August 11, 2020. The Elevation of Privilege vulnerability exists in the Netlogon Remote Protocol and can allow an unauthenticated attacker to obtain domain administrator access. The vulnerability has a CVSSv3 base score of 10 and is rated as critical by Microsoft.

The update had a planned two-phase release approach. In August, the initial phase of the update was made available. This would implement the changes, however, not begin enforcement, but would start to log connection that would be denied once enforcement is turned on. Guidance from Microsoft was to begin monitoring and identifying non-compliant connections and resolve any of the non-compliant scenarios before enabling enforcement. With a registry change you could turn on enforcement at any time once you are ready. Phase two was targeted for February 9, 2021 and would see an additional update that would enable the enforcement.

The release of proof-of-concept code and indications that threat actors could already be exploiting the vulnerability in the wild moved up the time table quickly and recommendations from the Cybersecurity & Infrastructure Security Agency (CISO) and other security experts urge more immediate actions. The CISA released Emergency Directive (ED) 20-04 on September 18 and the directive stated that all Windows servers with the domain controller role must resolve the vulnerability to be compliant with the directive by Monday September 21. Agencies under the CISA directive also had to prove compliance by Wednesday September 23.

Continuous Vulnerability Management – Is your process effective?

Many organizations believe they have a solid vulnerability remediation process in place. In reality, any company has room to improve on such processes. The recent Zerologon scramble touches on many of those areas that can be improved or should be re-evaluated.

Every organization should ask the following questions:

What is your SLA on vulnerability remediation?

The median time to exploit a vulnerability is 22 days according to research from the RAND Institute. According to the Verizon Data Breach Investigations Report from 2016, 50% of exploits will have occurred within 14-28 days of a patch being made available. Bluekeep is a very public example of how quickly an exploit can be developed. The update was made available on May 14, 2019 and multiple research teams had independently developed exploits by May 28, 2019 exactly 14 days after release of the update. If your Time to Patch is not targeting 14 days or less, you could be leaving your organization exposed to significant risk.

How are you prioritizing vulnerability remediation?

At the current rate of identification, the number of CVEs (Common Vulnerabilities and Exposures) identified in 2020 is likely to exceed 20,000. That is a lot of vulnerabilities to respond to. One common trap companies fall into is trying to reduce the amount of updates they need to resolve quickly vs those than can take a longer cycle. They often will use vendor severity and CVSS score to attempt to reduce the CVEs that need the quick turn around (14 days or less) by targeting vendor Critical or CVSSv3 base scores of 8.0 or higher. Recorded future released a top 10 list of CVEs exploited in 2019. The list included vulnerabilities dating all the way back to 2012. Two in particular come to mind when talking about prioritization. CVE-2017-11882 is a vulnerability that was exploited very nearly from day one. It was only rated as Important by Microsoft and has a CVSS score of 7.8. It was one of the top 10 exploited vulnerabilities according to Recorded Future’s 2019 top 10 exploited CVEs list. Adopting a Risk-based prioritization process to identify the real risk of vulnerabilities as there are many examples that could slip by if not scrutinized.

Does your organization have a well-defined process for priority vs regular maintenance?

Threat actors can move fast. When they do, we need to know what they are exploiting and be able to move quickly to resolve such vulnerabilities. If you have a good risk prioritization process you should be able to react when that prioritization identifies a critical risk. Having two well defined tracks in your process is important. You should have your regular vulnerability management process and should be predictable. Well established SLAs, criteria for what gets prioritized and when it needs to be resolved by. You also need a out of band or rapid response plan that can be triggered literally at a moments notice. In the case of Zerologon or previous situations like WannaCry, the need to respond quickly comes up and when it does it cannot be slowed by weighty discussion. Have a well-established quick response plan and make sure it reduces decision times, has well identified parties who are responsible and an action plan that can be rehearsed and executed quickly.

When to turn to an external service provider

Not every organization has the in-house expertise, the tools to monitor for and prioritize vulnerability risks, and the resources to continually monitor and research vulnerabilities to determine what course of action they should take. Having a managed service focused on risk prioritization and urgent vulnerability response is not a bad idea to augment your team. There are vulnerability management and threat intelligence companies that have products, but also can provide managed services in these areas. They specialize in these activities so you can focus on the day to day and when they prioritize an urgent item, you can respond quickly and confidently.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}