Onelogon Attack Exploits Microsoft Zerologon Patch Flaw

Onelogon Attack Exploits Microsoft Zerologon Patch Flaw

First seen 12 Aug 2026, 08:06 UTC Itnews.Auwww.usenix.org 79% similarity 67.5

Article Content

Browse articles
ThreatCluster

German researchers have discovered a new vulnerability named Onelogon, which exploits the previously patched Zerologon flaw (CVE-2020-1472) in Microsoft's Active Directory. The Onelogon attack can be executed using two methods: a 24-bit brute force attack requiring a low-privilege account, and a meet-in-the-middle attack that does not require prior access. Both methods can compromise an Active Directory account in approximately 30-37 minutes. Despite Microsoft releasing patches for Zerologon, the researchers found that the cryptographic implementation remains flawed, allowing the Onelogon attack to succeed. The vulnerability primarily affects organizations that have not implemented secure Remote Procedure Calls (RPCs), with scans revealing that many still allow vulnerable configurations. The researchers disclosed their findings to Microsoft but do not expect any fixes soon, advising users to adopt mitigation strategies instead.

Key Points: • Onelogon exploits the Zerologon vulnerability in Microsoft's Active Directory. • The attack can compromise accounts in 30-37 minutes using two distinct methods. • Microsoft's patches are insufficient, and many organizations remain vulnerable.

ThreatCluster AI How this analysis works

Timeline

2020-08-17
CVE-2020-1472 published
Microsoft's Zerologon vulnerability was officially disclosed, allowing full AD domain compromise.
Itnews.Au
2021-11-03
CVE-2020-1472 added to CISA KEV
CISA classified the Zerologon vulnerability as actively exploited, urging immediate attention.
Itnews.Au
2026-08-12
Onelogon attack disclosed
Researchers revealed the Onelogon vulnerability, which bypasses Microsoft's Zerologon patch, affecting AD accounts.
Itnews.Au

Community

Browse all →

Tracked Entities in This Story