LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2014-1812: Microsoft Windows Group Policy Preferences Password Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2014-1812 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Group Policy preferences. An authenticated attacker…

CVE-2014-1812 is a privilege-escalation vulnerability in Microsoft Windows Active Directory related to how Group Policy Preferences distribute configured passwords. An authenticated attacker who can obtain those preference data can decrypt the passwords and use them to raise privileges on the domain. The issue is tracked as known for ransomware use, so domain environments that still rely on Group Policy Preferences for password settings should treat it as a high-priority remediation item and confirm all details against the vendor advisory.

This guidance is for IT and security teams who need to inventory exposure, patch, and apply compensating controls until the vendor update is fully deployed.

How it works

The weakness is classed as CWE-255 (Credentials Management). Group Policy Preferences can store passwords for local accounts, services, or scheduled tasks and push those settings to domain-joined systems. The distribution mechanism left the stored credentials recoverable by an authenticated principal who could read the preference files or related Active Directory data.

An attacker who already has a foothold on the domain (for example a standard user or compromised workstation) can locate the Group Policy Preference objects that contain the encrypted password material, decrypt it using publicly understood methods for this class of flaw, and then reuse the recovered credentials. Those credentials often belong to local administrators or service accounts, giving the attacker a path to elevate privileges across the domain. Exact file paths, encryption details, and exploitation steps must be confirmed against the vendor advisory; do not rely on third-party write-ups alone.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Windows environments that use Active Directory and Group Policy Preferences to distribute passwords. Typical locations include domain controllers, member servers, and workstations that apply Group Policy Objects containing preference items for local user passwords, mapped drives with credentials, services, or scheduled tasks.

Telemetry signs of exploitation are those of credential theft and lateral movement after an authenticated foothold—sudden use of previously GPO-managed accounts, creation of new admin sessions, or ransomware staging—rather than a unique network signature. Correlate with your EDR and domain audit logs.

How to remediate

Apply the security updates Microsoft released for this vulnerability, following the vendor instructions referenced by CISA. Patch domain controllers and all systems that apply the affected Group Policy Preferences first, then verify installation across the estate.

If you can't patch immediately

Reduce risk with compensating controls until the vendor update is deployed everywhere.

If your data may have been exposed

Actively exploited privilege-escalation flaws, including those with known ransomware use, frequently precede domain-wide compromise and data theft. If you find evidence that Group Policy Preference passwords were readable or that elevated accounts were abused, treat the incident as a potential breach: isolate affected systems, rotate credentials, and follow your incident-response plan. You can run a free exposure scan of your email addresses against known breach data to check whether associated identities have appeared in prior dumps while you complete containment and recovery.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-255
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities