Skip to main content

Microsoft Active Directory Group Policy Preferences Elevation of Privilege Vulnerability

Last Update Date: 14 May 2014 14:46 Release Date: 14 May 2014 3151 Views

RISK: Medium Risk

TYPE: Servers - Network Management

TYPE: Network Management

An elevation of privilege vulnerability exists in the way that Active Directory distributes passwords that are configured using Group Policy preferences. An authenticated attacker who successfully exploited the vulnerability could decrypt the passwords and use them to elevate privileges on the domain.


Impact

  • Elevation of Privilege

System / Technologies affected

  • Microsoft Windows Vista
  • Microsoft Windows 7
  • Microsoft Windows 8 and Windows 8.1
  • Microsoft Windows Server 2008
  • Microsoft Windows Server 2008 R2
  • Microsoft Windows Server 2012 and Windows Server 2012 R2

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link