Skip to content

Zerologon

  • Initial patch Aug 11, 2020. Enforcement patch Feb 9, 2021.
  • CVE‑2020‑1472
  • Allows an unauthenticated user to authenticate to NRPC as the DC$ account.
  • Exploitation is destructive. Meaningful exploitation requires changing to DC$ computer password. There are other low impact ways zerologon can be exploited.

Check for the vulnerability using nxc without any exploitation.

nxc smb <target> -u '<username>' -p '<password>' -M zerologon