Zerologon (Aug–Sept 2020): Taking Over a Domain Controller in Seconds
Retrospective: this article looks back at events from September 2020, written in 2026 with the benefit of hindsight.
In August 2020, Microsoft patched CVE-2020-1472, a critical flaw in the Netlogon Remote Protocol used by Windows domain controllers. In September, researchers at Secura published details and named it Zerologon. It scored the maximum CVSS rating of 10.
What it allowed
A cryptographic weakness in how Netlogon used AES in a particular mode meant an attacker with network access to a domain controller could, in a few seconds, authenticate as the domain controller itself and reset its machine account password. From there, they could effectively take over the Active Directory domain — without any credentials.
The response
Public proof-of-concept code appeared quickly. The US Cybersecurity and Infrastructure Security Agency (CISA) issued Emergency Directive 20-04, requiring federal agencies to patch within days. Ransomware groups and state actors began exploiting it. Microsoft's fix rolled out in two phases, with an enforcement phase in February 2021 that required compatible devices.
Why it mattered for cloud teams
Most organizations running Microsoft 365 or Azure are hybrid: on-premises Active Directory synchronizes identities to Entra ID through Entra Connect, and sometimes domain controllers run as Azure VMs. Taking over on-premises AD can lead to cloud compromise — through synchronized accounts, Entra Connect servers, AD FS or password hash access.
Lessons in hindsight
- Domain controllers are Tier 0 assets and need emergency patching SLAs.
- Hybrid identity links on-prem risk to cloud risk.
- Segment domain controllers so only systems that need Netlogon can reach them.
- Monitor for exploitation with Defender for Identity, which added detections quickly.
Zerologon reinforced a theme of the decade: identity infrastructure is the crown jewel, and its oldest components can be its weakest.
- How to Patch and Monitor Domain Controllers in Hybrid Azure Environments How-To & Hardening
- Detecting Netlogon Exploitation: Defender for Cloud and Sentinel KQL Detection & Response
- CIO Brief: Hybrid Identity Means On-Prem Flaws Become Cloud Flaws CIO Briefings