CVE-2020-1472

ENISA EUVD: EUVD-2020-12346 ↗
Exploited in the Wild ✓ Confirmed 0-Day
Triaged: March 5, 2026 17 articles

EPSS Score

Source: FIRST.org · 2026-05-24
94.38%
probability
This CVE has a 94.38% probability of being exploited in the next 30 days.
0% Top 100.0th percentile of all CVEs 100%

CVSS v3.1

Source: NVD
5.5
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Temporal
Exploit Code Maturity
Proof-of-Concept
Remediation Level
Official Fix
Report Confidence
Confirmed
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C

Affected Products

Exploits & PoC

bvcyber/CVE-2020-1472

Test tool for CVE-2020-1472

1812
dirkjanm/CVE-2020-1472

PoC for Zerologon - all research credits go to Tom Tervoort of Secura

1294
risksense/zerologon

Exploit for zerologon cve-2020-1472

687
VoidSec/CVE-2020-1472

Exploit Code for CVE-2020-1472 aka Zerologon

395
bb00/zer0dump

Abuse CVE-2020-1472 (Zerologon) to take over a domain and then repair the local stored machine account password.

180
mstxq17/cve-2020-1472

cve-2020-1472 复现利用及其exp

113
zeronetworks/zerologon

Test script for CVE-2020-1472 for both RPC/TCP and RPC/SMB

61
k8gege/CVE-2020-1472-EXP

Ladon Moudle CVE-2020-1472 Exploit 域控提权神器

58
cube0x0/CVE-2020-1472

PoC CVE-2020-1472 — cube0x0/CVE-2020-1472

38
9 repos — triés par ⭐ Rechercher sur GitHub ↗

Signal Intelligence

Confidence
92%
EPSS 94.38%
CVSS v3.1 5.5
Mentions 17
Last Seen May 27, 2026

CNA Information

Analyst Note

CVE-2020-1472 (Zerologon) is a confirmed zero-day with widespread in-the-wild exploitation documented in 2020. Active attacks against domain controllers occurred immediately after disclosure, with exploitation preceding comprehensive patch availability across all affected systems. CERT-EU's urgent security advisory confirms critical exploitation in the wild.

Threat Actors 56

MuddyWater
apt_group Information theft and espionage 🇮🇷 IR
Lazarus Group
apt_group Information theft and espionage 🇰🇵 KP
Turla Group
apt_group Information theft and espionage Russian Federation
APT 29
apt_group Information theft and espionage 🇷🇺 RU
DarkHotel
apt_group Information theft and espionage 🇰🇷 KR
WIZARD SPIDER
apt_group Financial gain 🇷🇺 RU
Cobalt
apt_group Financial crime 🇷🇺 RU
APT37
apt_group Information theft and espionage 🇰🇵 KP
FIN7
apt_group Financial crime 🇷🇺 RU
APT32
apt_group Information theft and espionage 🇻🇳 VN
Cron
apt_group 🇷🇺 RU
SaintBear
apt_group Information theft and espionage 🇷🇺 RU
CHRYSENE
apt_group Information theft and espionage 🇮🇷 IR
Careto
apt_group Information theft and espionage 🇪🇸 ES
Leviathan
apt_group Information theft and espionage 🇨🇳 CN
BelialDemon
apt_group 🇷🇺 RU
Hacking Team
apt_group 🇮🇹 IT
Energetic Bear
apt_group Information theft and espionage 🇷🇺 RU
Nitro
apt_group Information theft and espionage 🇨🇳 CN
MAGNALLIUM
apt_group Sabotage and destruction 🇮🇷 IR
Ice Fog
apt_group Information theft and espionage 🇨🇳 CN
DNSpionage
apt_group Information theft and espionage 🇮🇷 IR
Kinsing
apt_group 🇷🇺 RU
HAZY TIGER
apt_group Information theft and espionage 🇮🇳 IN
TA505
apt_group Financial gain 🇷🇺 RU
Infy
apt_group Information theft and espionage 🇮🇷 IR
Naikon
apt_group Information theft and espionage 🇨🇳 CN
Wekby
apt_group Information theft and espionage 🇨🇳 CN
Evilnum
apt_group Information theft and espionage
TeamTNT
apt_group 🇩🇪 DE
ProjectSauron
apt_group Information theft and espionage 🇺🇸 US
Predatory Sparrow
apt_group Sabotage and destruction 🇮🇱 IL
PROMETHIUM
apt_group Information theft and espionage 🇹🇷 TR
Silence group
apt_group Financial crime 🇷🇺 RU
Pirate Panda
apt_group Information theft and espionage 🇨🇳 CN
GhostNet
apt_group Information theft and espionage 🇨🇳 CN
LUNAR SPIDER
apt_group 🇷🇺 RU
RAZOR TIGER
apt_group Information theft and espionage 🇮🇳 IN
RomCom
apt_group Financial gain 🇷🇺 RU
Putter Panda
apt_group Information theft and espionage 🇨🇳 CN
NetTraveler
apt_group Information theft and espionage 🇨🇳 CN
El Machete
apt_group Information theft and espionage 🇻🇪 VE
TeamXRat
apt_group 🇧🇷 BR
IXESHE
apt_group Information theft and espionage 🇨🇳 CN
Anchor Panda
apt_group Information theft and espionage 🇨🇳 CN
GCMAN
apt_group Financial crime 🇷🇺 RU
PowerPool
apt_group Information theft and espionage 🇷🇺 RU
Blue Termite
apt_group Information theft and espionage 🇨🇳 CN
Blackgear
apt_group Information theft and espionage 🇨🇳 CN
GC01
apt_group Financial gain 🇨🇦 CA
Rocke
apt_group 🇨🇳 CN
RedAlpha
apt_group Information theft and espionage 🇨🇳 CN
Scarab
apt_group Information theft and espionage 🇨🇳 CN
ZooPark
apt_group Information theft and espionage 🇮🇷 IR
Operation Shadow Force
apt_group 🇨🇳 CN
DEV-0586
apt_group Sabotage and destruction 🇷🇺 RU

Triage Info

Decided atMar 05, 2026