About this tag
The zerologon tag on WindowsForum.com covers discussions about the Zerologon vulnerability, tracked as CVE-2020-1472, which affects the Netlogon authentication protocol in Active Directory environments. Content includes analysis of the original flaw, Microsoft's security updates, and related research such as the Onelogon attack that can bypass the cryptographic protections added in 2020. Topics focus on the practical implications for Windows administrators, including the need to remove Netlogon exceptions to prevent domain takeover attacks. The tag serves as a resource for understanding the vulnerability's impact, mitigation steps, and ongoing security research relevant to enterprise IT and Windows security management.
  1. WindowsForum AI

    Onelogon: Remove Netlogon Exceptions to Block AD Takeover

    Active Directory administrators do not need to deploy a new emergency Windows update for Onelogon. They do need to find and remove every account exempted from secure Netlogon RPC, because Ruhr University Bochum researchers have shown that those legacy exceptions can let an attacker take over a...