Skip to content

ED 20-04, Mitigate Netlogon Elevation of Privilege Vulnerability from August 2020 Patch Tuesday

RetiredCISA · Emergency Directive · September 18, 2020

Summary

Required agencies to apply Microsoft's August 2020 update to every Windows domain controller by September 21, 2020, closing a Netlogon flaw that could let an attacker take over Active Directory, and to report completion.

Read it on www.cisa.gov

What FedXchange has recorded

No changes recorded. The watch records a new document and any change in its status.

Issuer
Cybersecurity and Infrastructure Security Agency (CISA)
Type
Emergency Directive
Number
ED 20-04
Issued
September 18, 2020
Status
Retired

Closed by its issuer (CISA's term for a directive that has done its job).

Retired by CISA on January 8, 2026, which found its required actions complete or covered by BOD 22-01.

Get new governance by email

A weekly email on Fridays, an alert on the day the watch finds something new, or both. Free.

Send me

We use your address only to send what you choose, and every email has a one-click unsubscribe. Read the privacy notice.