CISA Known Exploited Vulnerability

CVE-2014-1812 Ransomware

Microsoft · Windows

Microsoft Windows Group Policy Preferences Password Privilege Escalation Vulnerability

Date added
BOD 22-01 due date
CWE CWE-255
Ransomware Known

CISA description

Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Group Policy preferences. An authenticated attacker who successfully exploits the vulnerability could decrypt the passwords and use them to elevate privileges on the domain.

Required action

Apply updates per vendor instructions.