Onelogon Bypasses Microsoft’s Zerologon Patch

💡A Zerologon patch bypass could leave Windows-based AI infrastructure vulnerable despite remediation.
⚡ 30-Second TL;DR
What Changed
The Onelogon attack reportedly defeats Microsoft’s Zerologon patch.
Why It Matters
Organizations that depend on legacy Microsoft protocols may remain exposed even after applying the Zerologon patch. AI teams operating on Windows-based enterprise infrastructure should treat this as a potential security and availability risk.
What To Do Next
Use Microsoft Defender for Identity to review domain-controller alerts, identify systems using legacy protocols, and isolate or disable those protocols where operationally possible.
Key Points
- •The Onelogon attack reportedly defeats Microsoft’s Zerologon patch.
- •The vulnerability involves a legacy protocol.
- •Microsoft has no fix currently planned for that legacy protocol.
🧠 Deep Insight
AI-generated analysis for this event.
🔑 Enhanced Key Takeaways
- •The Onelogon vulnerability specifically targets the Netlogon Remote Protocol (MS-NRPC) in environments where legacy authentication methods remain enabled despite previous hardening efforts.
- •Security researchers identified that the exploit leverages a cryptographic flaw in how the protocol handles session key negotiation, effectively bypassing the 'Secure RPC' requirements introduced by the original Zerologon (CVE-2020-1472) patch.
- •Microsoft's decision to forgo a patch is based on the classification of the affected component as a deprecated legacy service that requires 'Domain Controller Enforcement Mode' to be fully mitigated.
- •Organizations are being advised to transition to 'Audit Mode' or 'Enforcement Mode' for Netlogon, though this carries a high risk of breaking legacy applications that rely on older, insecure authentication flows.
- •The attack vector is particularly dangerous for hybrid environments where on-premises Active Directory Domain Controllers are synchronized with cloud services, potentially allowing lateral movement from legacy segments to modern infrastructure.
🛠️ Technical Deep Dive
- The vulnerability exploits a weakness in the Netlogon authentication process where the client-side challenge-response mechanism can be manipulated if the server does not strictly enforce the use of secure RPC channels.
- It utilizes a modified version of the original Zerologon exploit script, specifically targeting the 'NetrServerPasswordSet2' or similar legacy RPC calls that were not fully deprecated in the initial patch cycle.
- The bypass occurs because the legacy protocol implementation fails to validate the integrity of the session key exchange when specific, older authentication flags are negotiated during the handshake.
- Successful exploitation allows an unauthenticated attacker to impersonate any computer account on the domain, including the Domain Controller itself, by setting a null password for the machine account.
🔮 Future ImplicationsAI analysis grounded in cited sources
⏳ Timeline
Weekly AI Recap
Read this week's curated digest of top AI events →
👉Related Updates
AI-curated news aggregator. All content rights belong to original publishers.
Original source: iTNews Australia ↗