CVE-2014-1812CISA KEV
Microsoft Windows Group Policy Preferences Password Privilege Escalation Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Group Policy preferences. An authenticated attacker who successfully exploits the vulnerability could decrypt the passwords and use them to elevate privileges on the domain.
- Product
- Windows
- Added to KEV
- 3 Nov 2021
- Federal remediation due
- 3 May 2022
- Known ransomware use
- Yes