VDB
BDU%3A2020-04016
BDU%3A2020-04016
PUBLISHED
CVSS 10 CRITICAL
Уязвимость реализации протокола Netlogon Remote Protocol (MS-NRPC) операционных систем Windows, позволяющая нарушителю повысить свои привилегии
Risk Scores
CVSS 2.0
10
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft Corp, Canonical Ltd., Сообщество свободного программного обеспечения, ООО «РусБИТех-Астра», Novell Inc., Fedora Project, Samba Team, АО "НППКТ", АО «Концерн ВНИИНС» | Windows Server 2012, Windows Server 2012 R2, Windows Server 2008 R2 Service Pack 1, Ubuntu, Windows Server 2016, Windows Server 2012 R2 (Server Core installation), Windows Server 2016 (Server Core installation), Debian GNU/Linux, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Astra Linux Special Edition (запись в едином реестре российских программ №369), Windows Server 1903 (Server Core Installation), OpenSUSE Leap, Windows Server 1909 (Server Core Installation), Fedora, Windows Server 2004 (Server Core Installation), Samba, ОСОН ОСнова Оnyx (запись в едином реестре российских программ №5913), Windows Server 2012 (Server Core installation), ОС ОН «Стрелец» (запись в едином реестре российских программ №6177) |
Timeline
- Aug 26, 2020 CVE Published
- Sep 17, 2020 PoC Published
- Oct 3, 2020 PoC Published
- Sep 24, 2024 CVE Updated
- Nov 29, 2024 PoC Published
- Jan 31, 2025 PoC Published
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Security Advisory
- Mar 19, 2026 Security Advisory
- Mar 19, 2026 Security Advisory
- Mar 19, 2026 Security Advisory
References
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1472 url
- https://www.cybersecurity-help.cz/vdb/SB2020081242 url
- https://security-tracker.debian.org/tracker/CVE-2020-1472 url
- https://nvd.nist.gov/vuln/detail/CVE-2020-1472 url
- https://wiki.astralinux.ru/astra-linux-se17-bulletin-2022-0819SE17 url
- https://wiki.astralinux.ru/astra-linux-se47-bulletin-2022-0926SE47 url
- https://wiki.astralinux.ru/astra-linux-se16-bulletin-20200921SE16MD url
- https://lists.opensuse.org/opensuse-security-announce/2020-09/msg00080.html url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/H4OTFBL6YDVFH2TBJFJIE4FMHPJEEJK3/ url
- https://ubuntu.com/security/notices/USN-4510-1 url
- https://ubuntu.com/security/notices/USN-4510-2 url
- https://поддержка.нппкт.рф/bin/view/ОСнова/Обновления/2.1/ url
- https://strelets.net/patchi-i-obnovleniya-bezopasnosti#16012023 url
- http://packetstormsecurity.com/files/160127/Zerologon-Netlogon-Privilege-Escalation.html url
- https://www.cisa.gov/sites/default/files/csv/known_exploited_vulnerabilities.csv url
- https://www.samba.org/samba/security/CVE-2020-1472.html advisory