ED 20-04, Mitigate Netlogon Elevation of Privilege Vulnerability from August 2020 Patch Tuesday
RetiredCISA · Emergency Directive · September 18, 2020
Summary
Required agencies to apply Microsoft's August 2020 update to every Windows domain controller by September 21, 2020, closing a Netlogon flaw that could let an attacker take over Active Directory, and to report completion.
What FedXchange has recorded
No changes recorded. The watch records a new document and any change in its status.
- Issuer
- Cybersecurity and Infrastructure Security Agency (CISA)
- Type
- Emergency Directive
- Number
- ED 20-04
- Issued
- September 18, 2020
- Status
- Retired
Closed by its issuer (CISA's term for a directive that has done its job).
Retired by CISA on January 8, 2026, which found its required actions complete or covered by BOD 22-01.
Get new governance by email
A weekly email on Fridays, an alert on the day the watch finds something new, or both. Free.