Microsoft Netlogon Privilege Escalation Vulnerability

Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller. An attacker who successfully exploits the vulnerability could run a specially crafted application on a device on the network. The vulnerability is also known under the moniker of Zerologon.

Published 24 Aug 2026Updated 24 Aug 2026156 sources
CVSS 0.0 ✓ VERIFIED REFERENCE△ CISA KEV

What happened

Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller. An attacker who successfully exploits the vulnerability could run a specially crafted application on a device on the network. The vulnerability is also known under the moniker of Zerologon.

Affected versions

Netlogon: See original advisory Fixed: See vendor advisory.

Why it matters

This source correlation may provide earlier visibility while structured CVE metadata is still being updated.

Detection & mitigation

  • Review the original advisory and validate affected versions.
  • Apply vendor-provided updates or mitigations when available.

Public PoC references

RepositoryAuthorFirst seenReference
Exploit-DB 49071ZeroLogon - Netlogon Elevation of PrivilegeWest Shepherd2020-11-18VerifiedPoC-in-GitHub · Tobey123/CVE-2020-1472-visualizer★ 0Tobey1232020-08-12CandidatePoC-in-GitHub · bvcyber/CVE-2020-1472Test tool for CVE-2020-1472★ 1832bvcyber2020-09-08CandidatePoC-in-GitHub · cube0x0/CVE-2020-1472★ 38cube0x02020-09-14CandidatePoC-in-GitHub · dirkjanm/CVE-2020-1472PoC for Zerologon - all research credits go to Tom Tervoort of Secura★ 1323dirkjanm2020-09-14CandidatePoC-in-GitHub · VoidSec/CVE-2020-1472Exploit Code for CVE-2020-1472 aka Zerologon★ 398VoidSec2020-09-14CandidatePoC-in-GitHub · risksense/zerologonExploit for zerologon cve-2020-1472★ 706risksense2020-09-14CandidatePoC-in-GitHub · bb00/zer0dumpAbuse CVE-2020-1472 (Zerologon) to take over a domain and then repair the local stored machine account password.★ 179bb002020-09-14CandidatePoC-in-GitHub · 0xkami/CVE-2020-1472CVE-2020-1472漏洞复现过程★ 20xkami2020-09-15CandidatePoC-in-GitHub · NAXG/CVE-2020-1472CVE-2020-1472复现流程★ 4NAXG2020-09-15CandidatePoC-in-GitHub · thatonesecguy/zerologon-CVE-2020-1472PoC for Zerologon (CVE-2020-1472) - Exploit★ 7thatonesecguy2020-09-15CandidatePoC-in-GitHub · k8gege/CVE-2020-1472-EXPLadon Moudle CVE-2020-1472 Exploit 域控提权神器★ 58k8gege2020-09-15CandidatePoC-in-GitHub · jiushill/CVE-2020-1472CVE-2020-1472★ 1jiushill2020-09-15CandidatePoC-in-GitHub · McKinnonIT/zabbix-template-CVE-2020-1472Zabbix Template to monitor for Windows Event Viewer event's related to Netlogon Elevation of Privilege Vulnerability - CVE-2020-1472. Monitors event ID's 5827, 5828 & 5829. See: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1472★ 1McKinnonIT2020-09-16CandidatePoC-in-GitHub · mstxq17/cve-2020-1472cve-2020-1472 复现利用及其exp★ 111mstxq172020-09-16CandidatePoC-in-GitHub · Fa1c0n35/CVE-2020-1472★ 0Fa1c0n352020-09-16CandidatePoC-in-GitHub · Fa1c0n35/SecuraBV-CVE-2020-1472★ 1Fa1c0n352020-09-16CandidatePoC-in-GitHub · CanciuCostin/CVE-2020-1472CVE-2020-1472 - Zero Logon vulnerability Python implementation★ 2CanciuCostin2020-09-16CandidatePoC-in-GitHub · 0xcccc666/cve-2020-1472_Tool-collectioncve-2020-1472_Tool collection★ 20xcccc6662020-09-16CandidatePoC-in-GitHub · murataydemir/CVE-2020-1472[CVE-2020-1472] Netlogon Remote Protocol Call (MS-NRPC) Privilege Escalation (Zerologon)★ 1murataydemir2020-09-16CandidatePoC-in-GitHub · npocmak/CVE-2020-1472https://github.com/dirkjanm/CVE-2020-1472★ 1npocmak2020-09-16CandidatePoC-in-GitHub · FaFcFF41/CVE-2020-1472★ 0FaFcFF412020-09-16CandidatePoC-in-GitHub · zeronetworks/zerologonTest script for CVE-2020-1472 for both RPC/TCP and RPC/SMB★ 61zeronetworks2020-09-17CandidatePoC-in-GitHub · sv3nbeast/CVE-2020-1472CVE-2020-1472复现时使用的py文件整理打包★ 10sv3nbeast2020-09-18CandidatePoC-in-GitHub · midpipps/CVE-2020-1472-EasyA simple implementation/code smash of a bunch of other repos★ 1midpipps2020-09-19CandidatePoC-in-GitHub · hectorgie/CVE-2020-1472★ 0hectorgie2020-09-19CandidatePoC-in-GitHub · johnpathe/zerologon-cve-2020-1472-notes★ 0johnpathe2020-09-20CandidatePoC-in-GitHub · t31m0/CVE-2020-1472★ 0t31m02020-09-21CandidatePoC-in-GitHub · grupooruss/CVE-2020-1472CVE 2020-1472 Script de validación★ 0grupooruss2020-09-24CandidatePoC-in-GitHub · striveben/CVE-2020-1472★ 5striveben2020-09-26CandidatePoC-in-GitHub · Fa1c0n35/CVE-2020-1472-02-★ 0Fa1c0n352020-09-28CandidatePoC-in-GitHub · Whippet0/CVE-2020-1472CVE-2020-1472★ 0Whippet02020-09-28CandidatePoC-in-GitHub · WiIs0n/Zerologon_CVE-2020-1472POC for checking multiple hosts for Zerologon vulnerability★ 11WiIs0n2020-09-29CandidatePoC-in-GitHub · Privia-Security/ADZeroZerologon AutoExploit Tool | CVE-2020-1472★ 22Privia-Security2020-09-29CandidatePoC-in-GitHub · Ken-Abruzzi/cve-2020-1472★ 0Ken-Abruzzi2020-09-30CandidatePoC-in-GitHub · rhymeswithmogul/Set-ZerologonMitigationProtect your domain controllers against Zerologon (CVE-2020-1472).★ 2rhymeswithmogul2020-09-30CandidatePoC-in-GitHub · shanfenglan/cve-2020-1472★ 2shanfenglan2020-10-10CandidatePoC-in-GitHub · maikelnight/zerologonCheck for events that indicate non compatible devices -> CVE-2020-1472★ 0maikelnight2020-10-15CandidatePoC-in-GitHub · CPO-EH/CVE-2020-1472_ZeroLogonCheckerC# Vulnerability Checker for CVE-2020-1472 Aka Zerologon★ 5CPO-EH2020-10-17CandidatePoC-in-GitHub · puckiestyle/CVE-2020-1472★ 0puckiestyle2020-10-21CandidatePoC-in-GitHub · mingchen-script/CVE-2020-1472-visualizer★ 1mingchen-script2020-11-05CandidatePoC-in-GitHub · JayP232/The_big_ZeroThe following is the outcome of playing with CVE-2020-1472 and attempting to automate the process of gaining a shell on the DC★ 0JayP2322020-11-10CandidatePoC-in-GitHub · b1ack0wl/CVE-2020-1472★ 1b1ack0wl2020-11-16CandidatePoC-in-GitHub · SaharAttackit/CVE-2020-1472★ 0SaharAttackit2020-12-23CandidatePoC-in-GitHub · wrathfulDiety/zerologonzerologon script to exploit CVE-2020-1472 CVSS 10/10★ 2wrathfulDiety2021-01-01CandidatePoC-in-GitHub · YossiSassi/ZeroLogon-Exploitation-Checkquick'n'dirty automated checks for potential exploitation of CVE-2020-1472 (aka ZeroLogon), using leading artifects in determining an actual exploitation of CVE-2020-1472. requires admin access to the DCs★ 7YossiSassi2021-01-07CandidatePoC-in-GitHub · sho-luv/zerologonZerologon Check and Exploit - Discovered by Tom Tervoort of Secura and expanded on @Dirkjanm's cve-2020-1472 coded example. This tool will check, exploit and restore password to original state★ 18sho-luv2021-01-20CandidatePoC-in-GitHub · hell-moon/ZeroLogon-ExploitModified the test PoC from Secura, CVE-2020-1472, to change the machine password to null★ 1hell-moon2021-03-01CandidatePoC-in-GitHub · Udyz/ZerologonExploit Code for CVE-2020-1472 aka Zerologon★ 1Udyz2021-04-06CandidatePoC-in-GitHub · itssmikefm/CVE-2020-1472★ 0itssmikefm2021-04-22CandidatePoC-in-GitHub · B34MR/zeroscanZeroscan is a Domain Controller vulnerability scanner, that currently includes checks for Zerologon (CVE-2020-1472), MS-PAR/MS-RPRN and SMBv2 Signing.★ 11B34MR2021-06-23CandidatePoC-in-GitHub · TheJoyOfHacking/SecuraBV-CVE-2020-1472★ 0TheJoyOfHacking2022-02-22CandidatePoC-in-GitHub · TheJoyOfHacking/dirkjanm-CVE-2020-1472★ 1TheJoyOfHacking2022-02-22CandidatePoC-in-GitHub · Anonymous-Family/Zero-day-scanningZero-day-scanning is a Domain Controller vulnerability scanner, that currently includes checks for Zero-day-scanning (CVE-2020-1472), MS-PAR/MS-RPRN and SMBv2 Signing.★ 1Anonymous-Family2022-03-03CandidatePoC-in-GitHub · Anonymous-Family/CVE-2020-1472Test tool for CVE-2020-1472★ 0Anonymous-Family2022-03-03CandidatePoC-in-GitHub · carlos55ml/zerologonSet of scripts, to test and exploit the zerologon vulnerability (CVE-2020-1472).★ 0carlos55ml2022-03-29CandidatePoC-in-GitHub · Rvn0xsy/ZeroLogonCVE-2020-1472 C++★ 84Rvn0xsy2022-08-31CandidatePoC-in-GitHub · guglia001/MassZeroLogonTool for mass testing ZeroLogon vulnerability CVE-2020-1472★ 3guglia0012022-09-30CandidatePoC-in-GitHub · likeww/MassZeroLogonTool for mass testing ZeroLogon vulnerability CVE-2020-1472★ 0likeww2022-09-30CandidatePoC-in-GitHub · dr4g0n23/CVE-2020-1472★ 0dr4g0n232022-11-22CandidatePoC-in-GitHub · Akash7350/CVE-2020-1472★ 2Akash73502023-04-30CandidatePoC-in-GitHub · c3rrberu5/ZeroLogon-to-ShellThis is a combination of the zerologon_tester.py code (https://raw.githubusercontent.com/SecuraBV/CVE-2020-1472/master/zerologon_tester.py) and the tool evil-winrm to get a shell.★ 0c3rrberu52023-08-14CandidatePoC-in-GitHub · logg-1/0logonMS-NRPC (Microsoft NetLogon Remote Protocol)/CVE-2020-1472★ 0logg-12024-01-07CandidatePoC-in-GitHub · whoami-chmod777/Zerologon-Attack-CVE-2020-1472-POC★ 2whoami-chmod7772024-01-25CandidatePoC-in-GitHub · metehangelgi/CVE-2020-1472-LABLab introduction to ZeroLogon★ 0metehangelgi2024-02-12CandidatePoC-in-GitHub · JolynNgSC/Zerologon_CVE-2020-1472★ 0JolynNgSC2024-03-21CandidatePoC-in-GitHub · blackh00d/zerologon-pocA script to exploit CVE-2020-1472 (Zerologon)★ 0blackh00d2024-06-06CandidatePoC-in-GitHub · TuanCui22/ZerologonWithImpacket-CVE2020-1472A practical proof-of-concept for CVE-2020-1472 (Zerologon) using the Impacket library to exploit Netlogon vulnerability and perform unauthorized domain controller access.★ 0TuanCui222024-12-28CandidatePoC-in-GitHub · PakwanSK/Simulating-and-preventing-Zerologon-CVE-2020-1472-vulnerability-attacks.Simulation of the Zerologon (CVE-2020-1472) vulnerability attack in Active Directory on Windows Server 2016 and the use of the Trend Micro Deep Security solution to prevent such attacks.★ 0PakwanSK2025-03-07CandidatePoC-in-GitHub · tdevworks/CVE-2020-1472-ZeroLogon-Demo-Detection-Mitigation★ 0tdevworks2025-05-17CandidatePoC-in-GitHub · 100HnoMeuNome/ZeroLogon-CVE-2020-1472-labExplicação e demonstração da vulnerabilidade ZeroLogon (CVE-2020-1472)★ 0100HnoMeuNome2025-10-04CandidatePoC-in-GitHub · nyambiblaise/Domain-Controller-DC-Exploitation-with-Metasploit-ImpacketEnd-to-end Domain Controller exploitation using Metasploit and Impacket: discovered DC10, exploited Zerologon (CVE-2020-1472), extracted NTLM hashes, gained SYSTEM shell, and established a Meterpreter session.★ 0nyambiblaise2025-10-18CandidatePoC-in-GitHub · mods20hh/ZeroLogon-PoC-DC-PwnZerologon (CVE-2020-1472) Proof-of-Concept application - Critical Active Directory vulnerability exploitation tool.★ 4mods20hh2025-12-06CandidatePoC-in-GitHub · commit2main/zerologon-labScripts for a lab environment demonstrating the Zerologon (CVE-2020-1472) vulnerability.★ 0commit2main2025-12-07CandidatePoC-in-GitHub · abdullah50i/internal-penetration-testing-project-using-MetasploitInitialized & connected PostgreSQL to Metasploit. Reconnoitered 10.1.16.0/24 with Nmap and imported results. Enumerated hosts/services using SYN, SMB & LDAP scanners. Exploited DC10 via ZeroLogon (CVE-2020-1472), dumped AD NTLM hashes with Impacket, performed Pass-the-Hash, then gained a Meterpreter reverse shell.★ 0abdullah50i2026-07-23CandidatePoC-in-GitHub · ckq7703/CVE-2020-1472CVE-2020-1472★ 0ckq77032026-08-25Candidate