Windows Netlogon
by Microsoft
CVEs (7)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-38124 | Cri | 0.59 | 9.0 | 0.01 | Oct 8, 2024 | Windows Netlogon Elevation of Privilege Vulnerability | ||
| CVE-2020-1472 | Med | 0.58 | 5.5 | 1.00 | KEV | Aug 17, 2020 | An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run a specially… | |
| CVE-2025-33070 | Hig | 0.53 | 8.1 | 0.07 | Jun 10, 2025 | Use of uninitialized resource in Windows Netlogon allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2019-1424 | Hig | 0.53 | 8.1 | 0.03 | Nov 12, 2019 | A security feature bypass vulnerability exists when Windows Netlogon improperly handles a secure communications channel, aka 'NetLogon Security Feature Bypass Vulnerability'. | ||
| CVE-2025-49716 | Hig | 0.49 | 7.5 | 0.01 | Jul 8, 2025 | Uncontrolled resource consumption in Windows Netlogon allows an unauthorized attacker to deny service over a network. | ||
| CVE-2023-21728 | Hig | 0.49 | 7.5 | 0.02 | Jan 10, 2023 | Windows Netlogon Denial of Service Vulnerability | ||
| CVE-2023-21526 | Hig | 0.48 | 7.4 | 0.01 | Jul 11, 2023 | Windows Netlogon Information Disclosure Vulnerability |
- risk 0.59cvss 9.0epss 0.01
Windows Netlogon Elevation of Privilege Vulnerability
- risk 0.58cvss 5.5epss 1.00
An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run a specially…
- risk 0.53cvss 8.1epss 0.07
Use of uninitialized resource in Windows Netlogon allows an unauthorized attacker to elevate privileges over a network.
- risk 0.53cvss 8.1epss 0.03
A security feature bypass vulnerability exists when Windows Netlogon improperly handles a secure communications channel, aka 'NetLogon Security Feature Bypass Vulnerability'.
- risk 0.49cvss 7.5epss 0.01
Uncontrolled resource consumption in Windows Netlogon allows an unauthorized attacker to deny service over a network.
- risk 0.49cvss 7.5epss 0.02
Windows Netlogon Denial of Service Vulnerability
- risk 0.48cvss 7.4epss 0.01
Windows Netlogon Information Disclosure Vulnerability