• Latest
  • Trending
Microsoft recalls the application phase of the Windows Zerologon patch – BleepingComputer

Microsoft warns of incoming Windows Zerologon patch application – BleepingComputer

15.01.2021
Samsung Electronics set to announce U.S. investment – BusinessKorea

Samsung Electronics set to announce U.S. investment – BusinessKorea

19.04.2021
Colton Underwood posts a peace sign in a selfie posted to his Instagram account … after its release

Colton Underwood posts a peace sign in a selfie posted to his Instagram account … after its release

19.04.2021
US regulator warns Peloton treadmill after child dies – WANE

US regulator warns Peloton treadmill after child dies – WANE

19.04.2021
Gold companies hit 7-week high with weaker dollar, lower returns

Gold companies hit 7-week high with weaker dollar, lower returns

19.04.2021
Carrie Underwood and CeCe Winans sounded like real angels in the ACM awards duo

Carrie Underwood and CeCe Winans sounded like real angels in the ACM awards duo

19.04.2021
Scott Rudin Fallout Steps Up With Sutton Foster’s Statement Emotional Video Of Late Assistant’s Twin – Variety

Scott Rudin Fallout Steps Up With Sutton Foster’s Statement Emotional Video Of Late Assistant’s Twin – Variety

19.04.2021
Bank of America survey: 74% of fund managers see Bitcoin as a bubble – Bitcoin markets and prices – Bitcoin News

Bank of America survey: 74% of fund managers see Bitcoin as a bubble – Bitcoin markets and prices – Bitcoin News

19.04.2021
Try a foldable Galaxy phone for 100 days risk-free – Android authority

Report: Samsung to launch Galaxy Z Fold 3, Z Flip 2 in July – Android authority

19.04.2021
American Idol: How Much Money Mariah Carey Made on the Series – Screen Rant

American Idol: How Much Money Mariah Carey Made on the Series – Screen Rant

19.04.2021
3 dead, 3 injured in Kenosha, Wis., Bar shooting

3 dead, 3 injured in Kenosha, Wis., Bar shooting

19.04.2021

The big celebration in Changjiang, Hainan province to host the traditional Chinese festival of Sanyuesan

19.04.2021
10 co-stars who fell in love on the set of a comedy |  TheThings – TheThings

Jay Z and Beyoncé and 9 other celebrity couples who had small private weddings – TheThings

19.04.2021
Monday, April 19, 2021
  • World
  • Economics
  • Sport
    • Basketball
    • Football
    • Nfl
    • Golf
    • F1
    • UFC
  • Technology
  • Culture
    • Arts
  • Media
    • Film
    • Celebs
    • TV
  • LifeStyle
    • Auto
  • Travel
OLTNEWS
  • World
  • Economics
  • Sport
    • Basketball
    • Football
    • Nfl
    • Golf
    • F1
    • UFC
  • Technology
  • Culture
    • Arts
  • Media
    • Film
    • Celebs
    • TV
  • LifeStyle
    • Auto
  • Travel
OLTNEWS
No Result
View All Result

Home » Technology » Microsoft warns of incoming Windows Zerologon patch application – BleepingComputer

Microsoft warns of incoming Windows Zerologon patch application – BleepingComputer

3 months ago
in Technology
0
0
SHARES
Share on WhatsappShare on Facebook

Related posts

Samsung Electronics set to announce U.S. investment – BusinessKorea

Samsung Electronics set to announce U.S. investment – BusinessKorea

19.04.2021
Try a foldable Galaxy phone for 100 days risk-free – Android authority

Report: Samsung to launch Galaxy Z Fold 3, Z Flip 2 in July – Android authority

19.04.2021

Microsoft today warned administrators that updates addressing the Windows Zerologon vulnerability will move into the application phase starting next month.

Zerologon is a 10/10 rated CVE-2020-1472 critical security vulnerability that, when successfully exploited, allows attackers to elevate privileges to the domain administrator and take control of the domain.

“We remind our customers that starting with the security update of February 9, 2021, we will enable domain controller enforcement mode by default,” said MSRC vice president of engineering Aanchal Gupta .

“DC Enforcement Mode requires all Windows and non-Windows devices to use secure RPC with the Netlogon secure channel, unless customers have explicitly allowed the account to be vulnerable by adding an exception for the non-compliant device.”

Patch deployment details

The hotfix released as part of the August 2020 Patch Tuesday updates enables secure remote procedure call (RPC) communication for computer accounts on Windows devices, trusted accounts, as well as all Windows and non-Windows domain controllers.

It also registers all non-compliant devices in the environment so that system administrators can troubleshoot or replace them before the application phase.

With the February 2021 updates, Microsoft will automatically begin enforcing secure RPC communications for all devices on the network and will no longer log non-compliant machines.

Microsoft also clarified the steps to take to protect its devices from Zerologon attacks after customers found the original instructions confusing.

The update plan described by Microsoft involves doing the following:

  1. UPDATE your domain controllers with an update released on August 11, 2020 or later.
  2. FIND which devices are making vulnerable connections by monitoring event logs.
  3. ADDRESS noncompliant devices making vulnerable connections.
  4. ENABLE the application mode to process CVE-2020-1472 in your environment.

Zerologon attacked

Shortly after news of a Zerologon patch was released in August 2020, researchers released ZeroLogon proof of concept exploits that allowed attackers to gain easy access to a domain controller.

With the release of the public exploits, Microsoft warned that threat actors quickly embraced them and started exploiting ZeroLogon in attacks.

A month later, Microsoft also added support for Zerologon exploit detection to Microsoft Defender for Identity, allowing security teams to detect on-premises attacks that attempt to abuse this critical vulnerability.

“Organizations that deploy Microsoft Defender for Identity (formerly Azure Advanced Threat Protection) or Microsoft 365 Defender (formerly Microsoft Threat Protection) are able to detect adversaries when they attempt to exploit this specific vulnerability against their domain controllers,” said Gupta said.

Share this:

  • Twitter
  • Facebook

Like this:

Like Loading...

Related

Previous Post

John Bishop donates 100 laptops to his old school

Next Post

Pfizer Temporarily Reduces European Vaccine Shipments While Improving Production Capacity – MarketWatch

Related Posts

Samsung Electronics set to announce U.S. investment – BusinessKorea
Technology

Samsung Electronics set to announce U.S. investment – BusinessKorea

19.04.2021
0

Samsung Electronics is expected to announce its US investment plan next month. Samsung Electronics is expected to announce its US...

Read more
Try a foldable Galaxy phone for 100 days risk-free – Android authority

Report: Samsung to launch Galaxy Z Fold 3, Z Flip 2 in July – Android authority

19.04.2021

The big celebration in Changjiang, Hainan province to host the traditional Chinese festival of Sanyuesan

19.04.2021

British man orders apples online, gets Apple iPhone instead – Deccan Herald

19.04.2021

REVIEW: Samsung Galaxy A52 – Khaleej Times

19.04.2021

Sony Xperia 1 III vs Samsung Galaxy S21 Ultra: which Android phone is right for you? – TechRadar

19.04.2021
Load More
Next Post
Pfizer Temporarily Reduces European Vaccine Shipments While Improving Production Capacity – MarketWatch

Pfizer Temporarily Reduces European Vaccine Shipments While Improving Production Capacity - MarketWatch

Recent Posts

  • Samsung Electronics set to announce U.S. investment – BusinessKorea
  • Colton Underwood posts a peace sign in a selfie posted to his Instagram account … after its release
  • US regulator warns Peloton treadmill after child dies – WANE
  • Gold companies hit 7-week high with weaker dollar, lower returns
  • Carrie Underwood and CeCe Winans sounded like real angels in the ACM awards duo

Archives

  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • EN

© 2020

No Result
View All Result
  • World
  • Economics
  • Sport
    • Basketball
    • Football
    • Nfl
    • Golf
    • F1
    • UFC
  • Technology
  • Culture
    • Arts
  • Media
    • Film
    • Celebs
    • TV
  • LifeStyle
    • Auto
  • Travel

© 2020

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.
%d bloggers like this: