CTD-000069

AD domain controller allowing vulnerable Netlogon secure channel connections

Medium
Active Directory
Privilege Escalation
v56

Signature Identity

CTD-000069
Threat ID
56
Version
IOE
Indicator Type

Threat Description

The Netlogon service on the remote host is vulnerable to the Zerologon vulnerability. An unauthenticated, remote attacker can exploit this, by spoofing a client credential to establish a secure channel to a domain controller using the Netlogon remote protocol (MS-NRPC). The attacker can then use this to change the computer’s Active Directory (AD) password, and escalate privileges to domain admin.

MITRE ATT&CK: Attack Tactics

Privilege Escalation

D3FEND: Defend Tactics

Application Configuration Hardening Software Update

Remediation

If your domain controllers are not yet protected against Zerologon, to prevent outages, follow this article.

If your environment has configured exceptions, to clean up the Allow list that contains devices that are allowed to use vulnerable Netlogon secure channel connections:

  1. In Group Policy, go to Computer Configuration > Windows Settings > Security Settings > Local Policies > Security Options.
  2. Search for “Domain controller: Allow vulnerable Netlogon secure channel connections”.
  3. Remove groups and accounts from the Allow list.
  4. Once the security group(s) is modified, the group policy must replicate to every DC.

Frequently Asked Questions

What does AD domain controller allowing vulnerable Netlogon secure channel connections mean?

The Netlogon service on a remote host is exposed to the Zerologon vulnerability, enabling an unauthenticated attacker to establish a secure channel with a domain controller using MS-NRPC. This allows the attacker to change the computer's Active Directory password and escalate privileges.

This vulnerability grants an unauthenticated attacker access to modify Active Directory passwords and elevate privileges, but does not directly grant administrative control. The attacker can use this access to gain unauthorized access to sensitive data and systems within the domain.

An attacker can exploit the Zerologon vulnerability to change Active Directory passwords, escalate privileges, and gain unauthorized access to sensitive data and systems within the domain. This allows the attacker to maintain persistence and potentially launch further attacks.

Cayosoft Guardian continuously monitors the Netlogon service for signs of the Zerologon vulnerability, flagging vulnerable connections as security issues so administrators can take corrective action.

Cayosoft Guardian alerts administrators to remove groups and accounts from the Allow list in Group Policy, preventing vulnerable Netlogon secure channel connections. This limits the attacker's ability to exploit the Zerologon vulnerability and maintain persistence.

Stop AD Threats As They Happen

Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack

Classification
Systems
Active Directory
Themes
Account protection Infrastructure
Attack Tactics
Privilege Escalation
Defend Tactics
Application Configuration Hardening Software Update
Indicator Types
IOE
Related Threats
CTD-000139
Kerberos Constrained Delegation: krbtgt Risks
Critical
CTD-000122
Active Directory Schema Update Permission Risks
Critical