Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-1472

Опубликовано: 17 авг. 2020
Источник: ubuntu
Приоритет: medium
EPSS Критический
CVSS2: 9.3
CVSS3: 5.5

Описание

An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run a specially crafted application on a device on the network. To exploit the vulnerability, an unauthenticated attacker would be required to use MS-NRPC to connect to a domain controller to obtain domain administrator access. Microsoft is addressing the vulnerability in a phased two-part rollout. These updates address the vulnerability by modifying how Netlogon handles the usage of Netlogon secure channels. For guidelines on how to manage the changes required for this vulnerability and more information on the phased rollout, see How to manage the changes in Netlogon secure channel connections associated with CVE-2020-1472 (updated September 28, 2020). When the second phase of Windows updates become available in Q1 2021, customer...

РелизСтатусПримечание
bionic

released

2:4.7.6+dfsg~ubuntu-0ubuntu2.19
devel

not-affected

2:4.12.5+dfsg-3ubuntu3
esm-infra-legacy/trusty

not-affected

2:4.3.11+dfsg-0ubuntu0.14.04.20+esm9
esm-infra/bionic

not-affected

2:4.7.6+dfsg~ubuntu-0ubuntu2.19
esm-infra/focal

not-affected

2:4.11.6+dfsg-0ubuntu1.4
esm-infra/xenial

not-affected

2:4.3.11+dfsg-0ubuntu0.16.04.30
focal

not-affected

2:4.11.6+dfsg-0ubuntu1.4
precise/esm

ignored

trusty

ignored

end of standard support
trusty/esm

released

2:4.3.11+dfsg-0ubuntu0.14.04.20+esm9

Показывать по

EPSS

Процентиль: 100%
0.94448
Критический

9.3 Critical

CVSS2

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
redhat
почти 5 лет назад

An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run a specially crafted application on a device on the network. To exploit the vulnerability, an unauthenticated attacker would be required to use MS-NRPC to connect to a domain controller to obtain domain administrator access. Microsoft is addressing the vulnerability in a phased two-part rollout. These updates address the vulnerability by modifying how Netlogon handles the usage of Netlogon secure channels. For guidelines on how to manage the changes required for this vulnerability and more information on the phased rollout, see How to manage the changes in Netlogon secure channel connections associated with CVE-2020-1472 (updated September 28, 2020). When the second phase of Windows updates become available in Q1 2021, custome...

CVSS3: 5.5
nvd
почти 5 лет назад

An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run a specially crafted application on a device on the network. To exploit the vulnerability, an unauthenticated attacker would be required to use MS-NRPC to connect to a domain controller to obtain domain administrator access. Microsoft is addressing the vulnerability in a phased two-part rollout. These updates address the vulnerability by modifying how Netlogon handles the usage of Netlogon secure channels. For guidelines on how to manage the changes required for this vulnerability and more information on the phased rollout, see How to manage the changes in Netlogon secure channel connections associated with CVE-2020-1472 (updated September 28, 2020). When the second phase of Windows updates become available in Q1 2021, customers

CVSS3: 10
msrc
больше 4 лет назад

Netlogon Elevation of Privilege Vulnerability

CVSS3: 5.5
debian
почти 5 лет назад

An elevation of privilege vulnerability exists when an attacker establ ...

suse-cvrf
больше 4 лет назад

Security update for samba

EPSS

Процентиль: 100%
0.94448
Критический

9.3 Critical

CVSS2

5.5 Medium

CVSS3

Уязвимость CVE-2020-1472