Skip to content
COOEY

EXPOSURES › CVE-2014-1812

CVE-2014-1812

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2014-1812 ↗
⌖ EXPLOITED IN THE WILD SHAME 72/100 ransomwareexploited-in-wildunpatched

An authenticated attacker can decrypt and escalate privileges within a Windows Active Directory domain via a Group Policy Preferences vulnerability.

CVE-2014-1812 allows authenticated attackers to decrypt and escalate privileges, potentially leading to domain compromise and significant data exposure. DIB organizations using older Windows versions must prioritize patching and review Group Policy configurations to prevent unauthorized access. Failure to address this vulnerability can result in non-compliance with CMMC and NIST 800-171.

Shame score — The vulnerability's exploitation in ransomware attacks and the ease of privilege escalation demonstrate a significant negligence in password management practices.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Group Policy preferences. An authenticated attacker who successfully exploits the vulnerability could decrypt the passwords and use them to elevate privileges on the domain.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.80
Critical security flaw in core Windows infrastructure
cooey ↗ severe-fallout -0.90
Damning security vulnerability
"An authenticated attacker who successfully exploits the vulnerability could decrypt the passwords and use them to elevate privileges on the domain."
AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized