← KEV catalog
CISA known exploited vulnerability

CVE-2014-1812

Microsoft Windows Group Policy Preferences Password Privilege Escalation Vulnerability

SOURCE FACT

Microsoft · Windows

Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Group Policy preferences. An authenticated attacker who successfully exploits the vulnerability could decrypt the passwords and use them to elevate privileges on the domain.

Required action

Apply updates per vendor instructions.

CISA notes

https://nvd.nist.gov/vuln/detail/CVE-2014-1812

View source evidence →

CHECK YOUR OUTSIDE-IN INVENTORY

Could this product be present?