Microsoft Issues Second Patch for Netlogon Vulnerability
A first phase patch for the critical vulnerability, tracked as CVE-2020-1472, was issued in August 2020. "The first phase of the patch was intended to address the vulnerability on two fronts: blocking both Windows-based domain members and non-Windows PCs that have been configured to disable signing/encryption as well as making changes to the Netlogon protocol for clients that cannot use the required signing/encryption," says Satnam Narang, staff research engineer at the security firm Tenable. The second patch completes the patching process for those who did not earlier implement enforcement ...