How to identify and neutralize the CVE-2020-1472 (ZeroLogon / Netlogon) vulnerability?

ZeroLogon, a new vulnerability in the Netlogon protocol

On Tuesday, August 11, 2020, Microsoft issued a security alert regarding the CVE-2020-1472 "Netlogon Elevation of Privilege" vulnerability, also known as "ZeroLogon" (see the bulletin).

This vulnerability affects the Netlogon remote protocol (also known as MS-NRPC for Microsoft Netlogon Remote Protocol) used by machines joined to a Windows domain.

What is the Netlogon protocol?

The Netlogon protocol is used when creating secure communication channels for operations related to authenticating an asset within a Windows domain. This includes, for example, connecting to remote machines joined to the domain, as well as updating a domain user account password.

The Netlogon protocol uses TCP port 135 as well as dynamic RPC (Remote Procedure Call) ports—that is, ports temporarily opened in the TCP 49152-65536 range—or exchanges over an SMB channel (TCP port 445).

How does a Netlogon exchange work?

A NetLogon exchange proceeds as follows:

  1. The client generates an 8-byte random word, called ChallengeClient, and sends this word to the Netlogon server, such as a domain controller.
  2. The server generates an 8-byte random word, called ChallengeServer, and sends this word to the client.
  3. The client and the server calculate a session key, named SessionKey, from two variables (a shared secret named ClientPasswordHash, the user's password hash on the domain, and a 16-byte word named ClientServerChallenge, formed by the concatenation of ClientChallenge and ServerChallenge) and two functions (an MD4 hash function, and a key derivation function denoted as KDF, which takes a key and a challenge as arguments, then calculates HMAC_SHA256(key, challenge), keeping the first 16 bytes). The formula is: SessionKey = KDF(ClientPasswordHash, ClientServerChallenge).
  4. Next, the client encrypts ClientChallenge with SessionKey, using AES-128-CFB8 (AES encryption with a 128-bit key, in Cipher Feedback mode with 8 bits per iteration) and obtains its identifier ClientIdentifier.
  5. The client sends its identifier ClientIdentifier to the server.
  6. The server, which already has SessionKey and ClientChallenge, verifies that it is able to decrypt ClientIdentifier.
  7. The server then encrypts its own challenge ServerChallenge with SessionKey, also using AES-128-CFB8, and thus obtains its identifier ServerIdentifier.
  8. The server sends its identifier ServerIdentifier to the client.
  9. The client, which also has SessionKey and ServerChallenge, verifies that it is able to decrypt ServerIdentifier.
  10. Secure communication is then established.

What is the Zerologon CVE-2020-1472 vulnerability?

The Zerologon CVE-2020-1472 vulnerability is linked to the use of the AES-128-CFB8 encryption technique.

AES-128-CFB8 adds 16 bytes to the beginning of the message to be encrypted via a randomly generated "initialization vector," also known as an "IV." Once this vector is obtained, AES-128-CFB8 encrypts the "IV + message" set with a key, iterating byte by byte over the entire message using successive AES encryption and XOR operations.

The researcher behind the CVE-2020-1472 vulnerability, Tom Tervoort, identified an issue in the implementation of AES-128-CFB8 within Netlogon: the initialization vector is systematically set to 16 null bytes (0x00). The initialization vector is therefore not random here, which violates cryptographic best practices.

Choosing this value of 16 null bytes (0x00) as the initialization vector means that if the message to be encrypted consists solely of null bytes (0x00), the resulting encrypted message via AES-128-CFB8 can also end up consisting entirely of null bytes (0x00). This depends solely on the value of the encryption key used, and if that key is random, this occurs statistically 1 out of 256 times.

However, in the case of the NetLogon protocol, the client has control over the message to be encrypted: it is ClientChallenge. This message can thus be arbitrarily set to 8 null bytes (0x00). Similarly, SessionKey, which is used to encrypt ClientChallenge with AES-128-CFB8, is assumed to be random by design. We therefore find ourselves in the exact conditions indicated previously, and the encryption of ClientChallenge by SessionKey and AES-128-CFB8 then statistically produces an 8-byte null message once every 256 attempts.

The CVE-2020-1472 vulnerability simply consists of "attempting" to send a ClientIdentifier message composed of 8 null bytes until the server accepts it. With a 1 in 256 chance of success, and using a script, this action takes only a few seconds.

In summary, CVE-2020-1472 is based on a cryptographic implementation flaw due to an initialization vector set to 16 null bytes, hence its nickname "ZeroLogon."

Which assets are affected by the CVE-2020-1472 vulnerability?

The systems affected by ZeroLogon / CVE-2020-1472 are Windows Server 2008 / 2012 / 2012 R2 / 2016 / 2019 / Server 1903, 1909, and 2004 assets that have not installed the August 11, 2020, security update, with particular attention to be paid to systems acting as domain controllers.

A detailed list of these items is available on the website of the National Cybersecurity Agency of France (ANSSI).

What is the impact of the ZeroLogon / CVE-2020-1472 vulnerability?

The ZeroLogon vulnerability allows a malicious user to take full remote control of a domain controller or to change a domain user's password.

Domain controllers must therefore be treated as a priority when deploying the latest security updates to neutralize this vulnerability.

How easy is it to exploit ZeroLogon / CVE-2020-1472?

Several exploits are available for free and publicly on the Internet, including this one on GitHub.

Kevin Beaumont, an analyst at Microsoft Threat Intelligence Global Engagement & Response, reported detecting attempts to exploit this vulnerability as early as September 26, 2020, confirming the likelihood of being targeted by a ZeroLogon attack.

How to neutralize ZeroLogon / CVE-2020-1472?

Microsoft has released the following security updates:

  • KB4571729 / KB4571719 for Windows Server 2008 R2
  • KB4571736 / KB4571702 for Windows Server 2012
  • KB4571703 / KB4571723 for Windows Server 2012 R2
  • KB4571694 for Windows Server 2016
  • KB4565349 for Windows Server 2019
  • KB4565351 for Windows Server version 1903 and version 1909
  • KB4566782 for Windows Server version 2004

Microsoft recommends applying these updates with a priority focus on domain controllers, and also encourages configuring Netlogon secure channel connections according to the procedure defined here.

Cyberwatch also recommends consulting the bulletin from the National Cybersecurity Agency of France CERTFR-2020-ALE-020 and performing a vulnerability scan on your information system as soon as possible, targeting at least your domain controllers.

Learn more

For further technical information on the vulnerability, you can also consult Tom Tervoort's post on the Secura website, or the episode of the NoLimitSecu podcast dedicated to the topic.

Thanks for submitting the form.