CVE-2020-1472
ENISA EUVD: EUVD-2020-12346 ↗
Exploited in the Wild
✓ Confirmed 0-Day
Triaged: March 5, 2026
17 articles
EPSS Score
Source: FIRST.org · 2026-05-24
94.38%
probability
This CVE has a 94.38% probability
of being exploited in the next 30 days.
0%
Top 100.0th percentile of all CVEs
100%
CVSS v3.1
Source: NVD5.5
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Temporal
Exploit Code Maturity
Proof-of-Concept
Remediation Level
Official Fix
Report Confidence
Confirmed
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C
Affected Products
Exploits & PoC
bvcyber/CVE-2020-1472
Test tool for CVE-2020-1472
1812
dirkjanm/CVE-2020-1472
PoC for Zerologon - all research credits go to Tom Tervoort of Secura
1294
risksense/zerologon
Exploit for zerologon cve-2020-1472
687
VoidSec/CVE-2020-1472
Exploit Code for CVE-2020-1472 aka Zerologon
395
bb00/zer0dump
Abuse CVE-2020-1472 (Zerologon) to take over a domain and then repair the local stored machine account password.
180
mstxq17/cve-2020-1472
cve-2020-1472 复现利用及其exp
113
zeronetworks/zerologon
Test script for CVE-2020-1472 for both RPC/TCP and RPC/SMB
61
k8gege/CVE-2020-1472-EXP
Ladon Moudle CVE-2020-1472 Exploit 域控提权神器
58
cube0x0/CVE-2020-1472
PoC CVE-2020-1472 — cube0x0/CVE-2020-1472
38
9 repos — triés par ⭐
Rechercher sur GitHub ↗
Part 2: An In-Depth Look at the Latest Vulnerability Threat Landscape (Attackers’ Edition)
Qualys
Jul 18, 2023
Qualys Top 20 Most Exploited Vulnerabilities
Qualys
Sep 04, 2023
Microsoft August 2020 Patch Tuesday fixes 2 zero-days, 120 flaws
BleepingComputer
Aug 11, 2020
Defense Lessons From the Black Basta Ransomware Playbook
Qualys
Feb 25, 2025
Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect
Tenable-Research
May 27, 2026
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations
Qualys
May 08, 2025
Qualys Response to CISA Alert: Binding Operational Directive 22-01
Qualys
Nov 09, 2021
Unpacking the CVEs in the FireEye Breach – Start Here First
Qualys
Feb 01, 2021
Solorigate/Sunburst : Theft of Cybersecurity Tools | FireEye Breach
Qualys
Dec 10, 2020
What Is Black Basta Ransomware and How to Mitigate Attack
Qualys
Sep 19, 2024
Conti Ransomware
Qualys
Nov 18, 2021
CISA Alert: Top Routinely Exploited Vulnerabilities
Qualys
Jul 29, 2021
Microsoft Netlogon Vulnerability (CVE-2020-1472 – Zerologon) – Automatically Discover, Prioritize and Remediate Using Qualys VMDR®
Qualys
Sep 15, 2020
Security Advisory 2020-046
CERT-EU
Sep 15, 2020
Signal Intelligence
Confidence
92%
EPSS
94.38%
CVSS v3.1
5.5
Mentions
17
Last Seen
May 27, 2026
CNA Information
Analyst Note
CVE-2020-1472 (Zerologon) is a confirmed zero-day with widespread in-the-wild exploitation documented in 2020. Active attacks against domain controllers occurred immediately after disclosure, with exploitation preceding comprehensive patch availability across all affected systems. CERT-EU's urgent security advisory confirms critical exploitation in the wild.
Threat Actors 56
MuddyWater
apt_group
Information theft and espionage
🇮🇷 IR
Lazarus Group
apt_group
Information theft and espionage
🇰🇵 KP
Turla Group
apt_group
Information theft and espionage
Russian Federation
APT 29
apt_group
Information theft and espionage
🇷🇺 RU
DarkHotel
apt_group
Information theft and espionage
🇰🇷 KR
WIZARD SPIDER
apt_group
Financial gain
🇷🇺 RU
Cobalt
apt_group
Financial crime
🇷🇺 RU
APT37
apt_group
Information theft and espionage
🇰🇵 KP
FIN7
apt_group
Financial crime
🇷🇺 RU
APT32
apt_group
Information theft and espionage
🇻🇳 VN
Cron
apt_group
🇷🇺 RU
SaintBear
apt_group
Information theft and espionage
🇷🇺 RU
CHRYSENE
apt_group
Information theft and espionage
🇮🇷 IR
Careto
apt_group
Information theft and espionage
🇪🇸 ES
Leviathan
apt_group
Information theft and espionage
🇨🇳 CN
BelialDemon
apt_group
🇷🇺 RU
Hacking Team
apt_group
🇮🇹 IT
Energetic Bear
apt_group
Information theft and espionage
🇷🇺 RU
Nitro
apt_group
Information theft and espionage
🇨🇳 CN
MAGNALLIUM
apt_group
Sabotage and destruction
🇮🇷 IR
Ice Fog
apt_group
Information theft and espionage
🇨🇳 CN
DNSpionage
apt_group
Information theft and espionage
🇮🇷 IR
Kinsing
apt_group
🇷🇺 RU
HAZY TIGER
apt_group
Information theft and espionage
🇮🇳 IN
TA505
apt_group
Financial gain
🇷🇺 RU
Infy
apt_group
Information theft and espionage
🇮🇷 IR
Naikon
apt_group
Information theft and espionage
🇨🇳 CN
Wekby
apt_group
Information theft and espionage
🇨🇳 CN
Evilnum
apt_group
Information theft and espionage
TeamTNT
apt_group
🇩🇪 DE
ProjectSauron
apt_group
Information theft and espionage
🇺🇸 US
Predatory Sparrow
apt_group
Sabotage and destruction
🇮🇱 IL
PROMETHIUM
apt_group
Information theft and espionage
🇹🇷 TR
Silence group
apt_group
Financial crime
🇷🇺 RU
Pirate Panda
apt_group
Information theft and espionage
🇨🇳 CN
GhostNet
apt_group
Information theft and espionage
🇨🇳 CN
LUNAR SPIDER
apt_group
🇷🇺 RU
RAZOR TIGER
apt_group
Information theft and espionage
🇮🇳 IN
RomCom
apt_group
Financial gain
🇷🇺 RU
Putter Panda
apt_group
Information theft and espionage
🇨🇳 CN
NetTraveler
apt_group
Information theft and espionage
🇨🇳 CN
El Machete
apt_group
Information theft and espionage
🇻🇪 VE
TeamXRat
apt_group
🇧🇷 BR
IXESHE
apt_group
Information theft and espionage
🇨🇳 CN
Anchor Panda
apt_group
Information theft and espionage
🇨🇳 CN
GCMAN
apt_group
Financial crime
🇷🇺 RU
PowerPool
apt_group
Information theft and espionage
🇷🇺 RU
Blue Termite
apt_group
Information theft and espionage
🇨🇳 CN
Blackgear
apt_group
Information theft and espionage
🇨🇳 CN
GC01
apt_group
Financial gain
🇨🇦 CA
Rocke
apt_group
🇨🇳 CN
RedAlpha
apt_group
Information theft and espionage
🇨🇳 CN
Scarab
apt_group
Information theft and espionage
🇨🇳 CN
ZooPark
apt_group
Information theft and espionage
🇮🇷 IR
Operation Shadow Force
apt_group
🇨🇳 CN
DEV-0586
apt_group
Sabotage and destruction
🇷🇺 RU
Triage Info
Decided atMar 05, 2026