A credential disclosure vulnerability exists in Netwrix Account Lockout Examiner (ALE) versions prior to 5.1, where remote, unauthenticated attackers can capture the Net-NTLMv1/v2 authentication challenge hash of the Domain Administrator account configured in the product. The vulnerability is triggered by generating a Kerberos Pre-Authentication Failed (Event ID 4771) event on a Domain Controller, causing the ALE service to authenticate to an attacker-controlled SMB server and leak the service account's credentials.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a Go-based proof-of-concept exploit for CVE-2020-15931, a credential disclosure vulnerability in Netwrix Account Lockout Examiner 4.1 (prior to 5.1) on Windows. The exploit consists of a single Go file ('cve-2020-15931.go') and supporting documentation. The exploit works by triggering a Kerberos Pre-Authentication failure (Event ID 4771) on a domain controller, which causes Netwrix ALE to connect to an attacker-controlled SMB server (implemented using Impacket's 'smbserver.py'). If the target is vulnerable, the Netwrix service account (typically a domain administrator) will attempt to authenticate to the attacker's SMB server, leaking the NTLMv1/v2 hash. The attacker can then capture this hash for offline cracking or relay attacks. The exploit requires the attacker to specify the domain, domain controller IP, and a valid username. The repository is structured with a single Go exploit file, a README with detailed usage instructions, and a license file. The exploit is a proof-of-concept and requires external dependencies (Go libraries and Impacket's Python SMB server).
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.