Itnews.Au
Onelogon Attack Exploits Microsoft Zerologon Patch Flaw
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
German researchers have discovered a new vulnerability named Onelogon, which exploits the previously patched Zerologon flaw (CVE-2020-1472) in Microsoft's Active Directory. The Onelogon attack can be executed using two methods: a 24-bit brute force attack requiring a low-privilege account, and a meet-in-the-middle attack that does not require prior access. Both methods can compromise an Active Directory account in approximately 30-37 minutes. Despite Microsoft releasing patches for Zerologon, the researchers found that the cryptographic implementation remains flawed, allowing the Onelogon attack to succeed. The vulnerability primarily affects organizations that have not implemented secure Remote Procedure Calls (RPCs), with scans revealing that many still allow vulnerable configurations. The researchers disclosed their findings to Microsoft but do not expect any fixes soon, advising users to adopt mitigation strategies instead.
Key Points: • Onelogon exploits the Zerologon vulnerability in Microsoft's Active Directory. • The attack can compromise accounts in 30-37 minutes using two distinct methods. • Microsoft's patches are insufficient, and many organizations remain vulnerable.