CVE-2014-1812Microsoft Windows Group Policy Preferences Password Privilege Escalation Vulnerability

PUBLISHEDvulnerability record
2021-11-03 · last modified June 21, 2025

Metadata

CVE ID:
CVE-2014-1812
Project:
Microsoft
Product:
Windows
Date Added:
2021-11-03
Due Date:
2022-05-03
Last Updated:
June 21, 2025

Vulnerability Name

Microsoft Windows Group Policy Preferences Password Privilege Escalation Vulnerability

Description

Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Group Policy preferences. An authenticated attacker who successfully exploits the vulnerability could decrypt the passwords and use them to elevate privileges on the domain.

Known To Be Used in Ransomware Campaigns?

Ransomware Status:
KNOWN

Action

Apply updates per vendor instructions.

Additional Notes

Related Weaknesses