Cybersecurity

Zerologon Vulnerability

In September 2020 Secura published an article disclosing a vulnerability in Windows Server (all known versions) Netlogon Remote Protocol. This vulnerability is known as CVE-2020-1472 or more commonly, Zerologon.

Zerologon poses a major threat to organizations as it targets the Domain Controller (DC). Attackers target domain controllers in order to gain access to the domain admin account and ultimately to control the hosts and servers connected to the data center. This enables threat actors to gain access to the entire compromised environment.

The attack utilizes flaws in an authentication protocol that validates the authenticity and identity of a domain-joined computer to the Domain Controller. Due to the incorrect use of an AES mode of operation it is possible to spoof the identity of any computer account (including that of the DC itself) and set an empty password for that account in the domain.

The exploitation consists of sending a large amount of authentication requests to a Domain Controller via NetLogon. These contain a client request which contains only 0’s for the credentials and results in a successful logon when a good key is chosen randomly by the server. A good key is chosen on average 1 in 256 times.

The exploit includes the utilization of a newly acquired connection in order to reset the password to a blank value, and then perform privilege escalation to Domain Admin.

You can find more information about Zerologon vulnerability here, and watch a webinar here.



----

Prepared by: CREAplus IT security Team 

News

New Release of Atalla AT1000 HSM (8.40)

u.trust 360The Utimaco Atalla Team has announced the release of the Atalla AT1000 hardware security module (HSM) version 8.40.

Read more ...

u.trust 360 - Remote Monitoring and Management of HSMs

u.trust 360With the Utimaco u.trust 360 administration platform you can remotely access your Atalla HSMs for real-time monitoring, configuration or reporting purposes on premises or in the cloud.

Read more ...

Technical Training for Utimaco HSM

utimaco LAN V5 4CREAplus, authorized Utimaco training partner, is going to deliver an online hands-on technical training for Utimaco HSM, on 4-5 February 2021.

Read more ...

CREAplus awarded ISO 27001 certification

Utimaco video IG 4CREAplus has been awarded the ISO 27001 certification (full name ISO/IEC 27001:2013).

Read more ...

Utimaco HSM MS CA Video Integration Guide

Utimaco video IG 4CREAplus has published a short video showing how easy it is to integrate an Utimaco hardware security module (HSM) with Microsoft AD CS.

Read more ...