cve-2014-1812

CRITICAL cisa_known_exploited
Description

Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Group Policy preferences. An authenticated attacker who successfully exploits the vulnerability could decrypt the passwords and use them to elevate privileges on the domain.

Timeline
Published
2021-11-03
Last Modified
2021-11-03
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cvss": 0.0,
  "datePublished": "2021-11-03",
  "dateUpdated": "2021-11-03",
  "description": "Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Group Policy preferences. An authenticated attacker who successfully exploits the vulnerability could decrypt the passwords and use them to elevate privileges on the domain.",
  "dueDate": "2022-05-03",
  "id": "CVE-2014-1812",
  "kev_catalogs": [
    "cisa"
  ],
  "knownRansomwareCampaignUse": "Known",
  "notes": "https://nvd.nist.gov/vuln/detail/CVE-2014-1812",
  "product": "Windows",
  "requiredAction": "Apply updates per vendor instructions.",
  "severity": "CRITICAL",
  "source": "cisa_known_exploited",
  "title": "Microsoft Windows Group Policy Preferences Password Privilege Escalation Vulnerability",
  "vendor": "Microsoft"
}
Enrichment data
View JSON API Download JSON