cve-2014-1812
CRITICAL cisa_known_exploited
Description
Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Group Policy preferences. An authenticated attacker who successfully exploits the vulnerability could decrypt the passwords and use them to elevate privileges on the domain.
Timeline
- Published
- 2021-11-03
- Last Modified
- 2021-11-03
CVSS Details
CVSS details not available.
Affected Products
No product information available.
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"cvss": 0.0,
"datePublished": "2021-11-03",
"dateUpdated": "2021-11-03",
"description": "Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Group Policy preferences. An authenticated attacker who successfully exploits the vulnerability could decrypt the passwords and use them to elevate privileges on the domain.",
"dueDate": "2022-05-03",
"id": "CVE-2014-1812",
"kev_catalogs": [
"cisa"
],
"knownRansomwareCampaignUse": "Known",
"notes": "https://nvd.nist.gov/vuln/detail/CVE-2014-1812",
"product": "Windows",
"requiredAction": "Apply updates per vendor instructions.",
"severity": "CRITICAL",
"source": "cisa_known_exploited",
"title": "Microsoft Windows Group Policy Preferences Password Privilege Escalation Vulnerability",
"vendor": "Microsoft"
}
Enrichment data
Aggregated bundle (all enrichments)