Lucene search

K
cisaCISACISA:E5A33B5356175BB63C2EFA605346F8C7
HistoryFeb 10, 2021 - 12:00 a.m.

Microsoft Launches Phase 2 Mitigation for Netlogon Remote Code Execution Vulnerability (CVE-2020-1472)

2021-02-1000:00:00
us-cert.cisa.gov
117

0.467 Medium

EPSS

Percentile

97.5%

Microsoft addressed a critical remote code execution vulnerability affecting the Netlogon protocol (CVE-2020-1472) on August 11, 2020. Beginning with the February 9, 2021 Security Update release, Domain Controllers will be placed in enforcement mode. This will require all Windows and non-Windows devices to use secure Remote Procedure Call (RPC) with Netlogon secure channel or to explicitly allow the account by adding an exception for any non-compliant device.

CISA encourages users and administrators to review the Microsoft security update and apply the necessary updates.

This product is provided subject to this Notification and this Privacy & Use policy.

Please share your thoughts.

We recently updated our anonymous product survey; we’d welcome your feedback.