RaqibCTI
CVE

CVE-2014-1812

P1⬤ KNOWN RANSOMWARE USE
Microsoft Windows Group Policy Preferences Password Privilege Escalation Vulnerability
Microsoft · Windows
Date added (CISA)
2021-11-03
Remediation due
2022-05-03
Known ransomware use
Yes
Remediation priority
P1known ransomware use · past CISA due date

Description

Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Group Policy preferences. An authenticated attacker who successfully exploits the vulnerability could decrypt the passwords and use them to elevate privileges on the domain.

Source: NVD ↗ · CISA KEV Catalog ↗