Junglewise Threat Intelligence

CVE-2014-1812: Microsoft Windows Group Policy Preferences Password Privilege Escalation Vulnerability

CVE-2014-1812 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2021-11-03

Technologies: Microsoft Windows Server 2008, Microsoft Windows Vista, Microsoft Windows, Microsoft Windows 8.1, Microsoft Windows Server 2012, Microsoft Windows 7. Vendors: Microsoft.

Executive brief

Microsoft Windows Group Policy Preferences fails to properly handle the distribution of passwords, allowing authenticated users to obtain sensitive credentials from the SYSVOL share. An attacker can decrypt these credentials to escalate privileges to domain administrator levels.

Affected products

  • Microsoft Windows Vista SP2
  • Microsoft Windows Server 2008 SP2, R2 SP1
  • Microsoft Windows 7 SP1
  • Microsoft Windows 8
  • Microsoft Windows 8.1
  • Microsoft Windows Server 2012 Gold, R2

Timeline

  • 2014-05-13: disclosed: MS14-025 advisory published by Microsoft
  • 2014-05-13: patched: Microsoft released security updates to address the vulnerability
  • 2014-05: exploited: First known exploitation in the wild reported
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats