Vulnerability threat dossier

CVE-2020-1472

oraclezfs storage appliance kit

An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run a specially crafted application on a device on the network. To exploit the vulnerability, an unauthenticated attacker would be required to use MS-NRPC to connect to a domain controller to obtain domain administrator access. Microsoft is addressing the vulnerability in a phased two-part rollout. These updates address the vulnerability by modifying how Netlogon handles the usage of Netlogon secure channels. For guidelines on how to manage the changes required for this vulnerability and more information on the phased rollout, see How to manage the changes in Netlogon secure channel connections associated with CVE-2020-1472 (updated September 28, 2020). When the second phase of Windows updates become available in Q1 2021, customers will be notified via a revision to this security vulnerability. If you wish to be notified when these updates are released, we recommend that you register for the security notifications mailer to be alerted of content changes to this advisory. See Microsoft Technical Security Notifications.

VTP deterministic threat61.9of 100 · CVSS excluded

VTP analyst assessment

Microsoft Netlogon privilege escalation

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence95%
Public exploitation · VTP factKEV

Assessment

CVE-2020-1472 is listed as known exploited by CISA KEV and ENISA EU KEV. A vulnerable Netlogon secure-channel connection to a domain controller can let an unauthenticated network attacker gain elevated domain privileges. CISA also records known ransomware campaign use.

Why it matters

  • A vulnerable domain controller can give an attacker a direct route to high-value Active Directory control.
  • Global known exploitation makes remediation and exposure reduction important where affected Netlogon implementations remain in use.

Evidence

1 record references and 1 source references passed trusted post-response validation. The current deterministic record contains 1 independent evidence group.

Uncertainties

The cited KEV listings establish global exploitation, not activity against a specific organization.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

If you operate Windows domain controllers or listed compatible implementations, verify vendor remediation and enforce the required Netlogon secure-channel protections.

AI baseline history (1)
  1. BASELINE ASSESSED
    Microsoft Netlogon privilege escalationgpt-5.6-terra · low
Technical severityMEDIUMCVSS 5.5 · technical context
Public exploitationKEVGlobal public evidence
Exploit maturityTECHNICAL DETAILSReliability not implied
EPSS0.99100th percentile · prediction
Evidence confidence95%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    CISA KEV lists this vulnerability as known to be exploited globally.

  2. 02

    EPSS is 0.99; this is predictive context, not exploitation evidence.

  3. 03

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

RESEARCH PUBLICATIONNew technical research
KEV ADDEDCISA KEV entry added
03

Claim provenance

Evidence and source independence

3publications detected
3underlying evidence chains

2 primary sources · 0 dependent secondary reports · 1 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimACTIVE EXPLOITATIONENISA EU KEV LISTED
95%claim confidence
INDEPENDENTcatalog:enisa-eu-kev:CVE-2020-1472ACTIVE
Evidence
04

Event history

Threat timeline

  1. 10:0017 Sept
    RESEARCH PUBLICATION

    New technical research

    Cisco Talos published evidence linked to CVE-2020-1472.

  2. 00:0003 Nov
    ACTIVE EXPLOITATION

    ENISA EU KEV entry added

    ENISA EU KEV reports known exploitation. VTP imported this historical entry as source baseline. This is public intelligence, not a VTP sensor observation.

  3. 00:0003 Nov
    KEV ADDED

    CISA KEV entry added

    CISA lists global known exploitation. This is not a VTP sensor observation.

05

Original publications

Source record

Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use

Ransomware incidents in Japan rose 4.7% year over year. The Gentlemen was the most active group, with leak-site listings more than doubling from January to July. Qilin ranked second and appeared to use AI, while SMEs with capital under JPY 1 billion represented 80% of victims.

CVE-2020-1472CVE-2025-2479CVE-2025-24799
Separate evidence group
Original

Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network

Berlin's state government has confirmed that it is the target of an extortion attempt following the August compromise of the city's state administrative network, and said it will not meet the extortionists' demands. The same statement disclosed that forensic work had found further data outflows in the portfolio of the Senate Department for Mobility, Transport, Climate Protection and Environment

CVE-2020-1472
Separate evidence group
Original

ENISA EU KEV catalog membership for CVE-2020-1472

ENISA EU KEV lists this vulnerability as known to be exploited. This is public intelligence, not a VTP sensor observation.

CVE-2020-1472
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score61.9vtp-threat-v1-public
Public exploitation30 / 30
EPSS prediction19.88 / 20
Exploit availability2.5 / 15
Source independence7.5 / 15
Intelligence recency2 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
5.5 · MEDIUM
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE
Unknown
CPE records
23
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.