Glossary
Zerologon
Zerologon (CVE-2020-1472) is a critical flaw in the Netlogon protocol that let attackers reset a domain controller's machine password.
Zerologon, tracked as CVE-2020-1472, is a critical vulnerability in the Netlogon Remote Protocol caused by a flawed use of cryptography in its authentication handshake. The flaw allowed an attacker with network access to a domain controller to bypass authentication entirely and set the domain controller's own computer account password to a known, empty value, without needing any prior credentials.
This matters because resetting the domain controller's machine password effectively hands an attacker the ability to impersonate the DC itself, enabling a direct path to full domain compromise, including DCSync-style credential extraction. Microsoft patched the underlying flaw and later enforced secure Netlogon channel requirements by default; hardening requires ensuring all domain controllers and devices are fully patched and that Netlogon secure channel enforcement is active rather than left in compatibility mode.