Executive brief
Microsoft Windows Group Policy Preferences fails to properly handle the distribution of passwords, allowing authenticated users to obtain sensitive credentials from the SYSVOL share. An attacker can decrypt these credentials to escalate privileges to domain administrator levels.
Affected products
- Microsoft Windows Vista SP2
- Microsoft Windows Server 2008 SP2, R2 SP1
- Microsoft Windows 7 SP1
- Microsoft Windows 8
- Microsoft Windows 8.1
- Microsoft Windows Server 2012 Gold, R2
Timeline
- 2014-05-13: disclosed: MS14-025 advisory published by Microsoft
- 2014-05-13: patched: Microsoft released security updates to address the vulnerability
- 2014-05: exploited: First known exploitation in the wild reported
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog