VDB
BDU%3A2020-04016
BDU%3A2020-04016
PUBLISHED
CVSS 10 CRITICAL
Уязвимость реализации протокола Netlogon Remote Protocol (MS-NRPC) операционных систем Windows, позволяющая нарушителю повысить свои привилегии
Risk Scores
CVSS 2.0
10
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft Corp, Canonical Ltd., Сообщество свободного программного обеспечения, ООО «РусБИТех-Астра», Novell Inc., Fedora Project, Samba Team, АО "НППКТ", АО «Концерн ВНИИНС» | Windows Server 2012, Windows Server 2012 R2, Windows Server 2008 R2 Service Pack 1, Ubuntu, Windows Server 2016, Windows Server 2012 R2 (Server Core installation), Windows Server 2016 (Server Core installation), Debian GNU/Linux, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Astra Linux Special Edition (запись в едином реестре российских программ №369), Windows Server 1903 (Server Core Installation), OpenSUSE Leap, Windows Server 1909 (Server Core Installation), Fedora, Windows Server 2004 (Server Core Installation), Samba, ОСОН ОСнова Оnyx (запись в едином реестре российских программ №5913), Windows Server 2012 (Server Core installation), ОС ОН «Стрелец» (запись в едином реестре российских программ №6177) | |
| Microsoft Corp, Canonical Ltd., Сообщество свободного программного обеспечения, ООО «РусБИТех-Астра», Novell Inc., Fedora Project, Samba Team, АО «НППКТ», АО «Концерн ВНИИНС» | Windows Server 2012, Windows Server 2012 R2, Windows Server 2008 R2 Service Pack 1, Ubuntu, Windows Server 2016, Windows Server 2012 R2 (Server Core installation), Windows Server 2016 (Server Core installation), Debian GNU/Linux, Windows Server 2008 R2 Service Pack 1 (Server Core installation), Windows Server 2019, Windows Server 2019 (Server Core installation), Astra Linux Special Edition (запись в едином реестре российских программ №369), Windows Server 1903 (Server Core Installation), OpenSUSE Leap, Windows Server 1909 (Server Core Installation), Fedora, Windows Server 2004 (Server Core Installation), Samba, ОСОН ОСнова Оnyx (запись в едином реестре российских программ №5913), Windows Server 2012 (Server Core installation), ОС ОН «Стрелец» (запись в едином реестре российских программ №6177) |
Timeline
- Aug 26, 2020 CVE Published
- Sep 17, 2020 PoC Published
- Oct 3, 2020 PoC Published
- Sep 24, 2024 CVE Updated
- Nov 29, 2024 PoC Published
- Jan 31, 2025 PoC Published
- Sep 23, 2026 Distribution Patch
- Sep 23, 2026 Distribution Patch
- Sep 23, 2026 Security Advisory
- Sep 23, 2026 Security Advisory
- Sep 23, 2026 Security Advisory
- Sep 23, 2026 Security Advisory
References
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1472 advisory
- https://www.cybersecurity-help.cz/vdb/SB2020081242 url
- https://security-tracker.debian.org/tracker/CVE-2020-1472 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-1472 url
- https://wiki.astralinux.ru/astra-linux-se17-bulletin-2022-0819SE17 advisory
- https://wiki.astralinux.ru/astra-linux-se47-bulletin-2022-0926SE47 advisory
- https://wiki.astralinux.ru/astra-linux-se16-bulletin-20200921SE16MD advisory
- https://lists.opensuse.org/opensuse-security-announce/2020-09/msg00080.html advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/H4OTFBL6YDVFH2TBJFJIE4FMHPJEEJK3/ advisory
- https://ubuntu.com/security/notices/USN-4510-1 advisory
- https://ubuntu.com/security/notices/USN-4510-2 advisory
- https://поддержка.нппкт.рф/bin/view/ОСнова/Обновления/2.1/ url
- https://strelets.net/patchi-i-obnovleniya-bezopasnosti#16012023 url
- http://packetstormsecurity.com/files/160127/Zerologon-Netlogon-Privilege-Escalation.html url
- https://www.cisa.gov/sites/default/files/csv/known_exploited_vulnerabilities.csv url
- https://www.samba.org/samba/security/CVE-2020-1472.html advisory