CVE-2014-1812

CVSS 2.0 Score 9.0 of 10 (high)

Details

Published May 14, 2014
Updated: Dec 19, 2024
CWE ID 255

Summary

CVE-2014-1812 is a vulnerability affecting the Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2. This issue arises due to improper handling of password distribution, enabling remote authenticated users to access sensitive credential information. By leveraging this vulnerability, attackers can elevate their privileges and obtain the SYSVOL share, resulting in significant security implications. This vulnerability was exploited in the wild in May 2014 and is referred to as the "Group Policy Preferences Password Elevation of Privilege Vulnerability."

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows Server 2008
  • Microsoft Windows 7
  • Microsoft Windows 8.1
  • Microsoft Windows Vista
  • Microsoft Windows Server 2012

Affected Vendors

  • Microsoft