CVE-2014-1812
Act now ● On CISA KEV — actively exploited used in ransomware
Actively exploited — on the CISA KEV list.
CVSS base
—
EPSS — probability of exploitation (30 days)
64.9%
99.2th percentile
CISA KEV
Listed
Added 2021-11-03 · patch by 2022-05-03
Weakness / dates
—
Published — · modified —
Description
Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Group Policy preferences. An authenticated attacker who successfully exploits the vulnerability could decrypt the passwords and use them to elevate privileges on the domain.