CISA Known Exploited Vulnerability
This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.
Remediation Deadline: May 3, 2022
High
CISA KEVRansomwareCVE-2014-1812
Microsoft—Windows
Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Group Policy preferences. An authenticated attacker who successfully exploits the vulnerability could decrypt the passwords and use them to elevate privileges on the domain.
Required Action
https://nvd.nist.gov/vuln/detail/CVE-2014-1812
Vulnerability Overview
- Severity
- High
- CISA KEV
- Yes
- Ransomware
- Known
- Published
- Nov 3, 2021
- KEV Added
- Nov 3, 2021
- Due Date
- May 3, 2022
- Related Articles
- 0
Vendor
Microsoft
Windows