Netskope Threat Labs

CVE-2020-1472

ATP Sandbox Adv. HeuristicsAVNetskope IPS

This detection identifies exploitation attempts targeting CVE-2020-1472, which has a MEDIUM severity rating. A vulnerability in the Netlogon Remote Protocol (MS-NRPC) lets an unauthenticated cyberattacker establish a vulnerable Netlogon secure channel connection to a domain controller and run specially crafted applications to obtain domain administrator access. Microsoft addressed the flaw, known as ZeroLogon, by changing how Netlogon handles secure channel connections.

First seen
January 2022
Last seen
October 2026
Alert Name
Binary.Exploit.CVE-2020-1472
ByteCode-MSIL.Exploit.CVE-2020-1472
Document-HTML.Exploit.CVE-2020-1472
Dropped:Generic.Exploit.CVE-2020-1472.2.31B4EB30
Dump:Generic.Exploit.CVE-2020-1472.2.84F9EBC0
Dump:Generic.Exploit.CVE-2020-1472.2.E1425B8C
Generic.Exploit.CVE-2020-1472.1.1673A4C9
Generic.Exploit.CVE-2020-1472.1.3B3232E4
Generic.Exploit.CVE-2020-1472.1.3F2071DA
Generic.Exploit.CVE-2020-1472.1.41AC6328