Vulnerability record · CVE-2014-1812 · published 14 May 2014
CVE-2014-1812: Microsoft Windows Group Policy Preferences credential exposure and privilege escalation
Microsoft · Windows 7
Group Policy Preferences in multiple Windows versions stored and distributed passwords in a way that did not properly protect them, allowing any authenticated user with access to the SYSVOL share to recover credential material. Because those credentials were often privileged domain accounts, this flaw matters as a straightforward path from a low-privileged domain account to domain administrator.
Description
The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does not properly handle distribution of passwords, which allows remote authenticated users to obtain sensitive credential information and consequently gain privileges by leveraging access to the SYSVOL share, as exploited in the wild in May 2014, aka "Group Policy Preferences Password Elevation of Privilege Vulnerability."
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityIt is in CISA KEV with known ransomware use, has a very high EPSS score, and yields privileged domain credentials to any authenticated user.
What it is
Group Policy Preferences in multiple Windows versions stored and distributed passwords in a way that did not properly protect them, allowing any authenticated user with access to the SYSVOL share to recover credential material. Because those credentials were often privileged domain accounts, this flaw matters as a straightforward path from a low-privileged domain account to domain administrator.
Impact
An attacker who can read SYSVOL obtains plaintext or weakly protected credentials for accounts configured in Group Policy Preferences, then uses them to gain privileges, potentially up to domain administrator.
Attack surface
Reached over the network via the SYSVOL share, which is readable by authenticated domain users; no user interaction is required. The CVSS vector confirms network access with low privileges and no UI.
Exploitation
Listed in CISA KEV with known ransomware campaign use, and EPSS shows a high 30-day probability (0.651, 99.2nd percentile). The description states it was exploited in the wild in May 2014.
What to do
- Apply the MS14-025 update to remove the ability to set passwords through Group Policy Preferences and prevent new credential distribution.
- Remove existing Group Policy Preferences password entries from all GPOs and rotate every credential that was ever stored in them.
- Restrict and audit SYSVOL read access, and monitor for unexpected reads of Groups.xml and related preference files.
- Where legacy GPP password use cannot be removed immediately, migrate those accounts to managed service accounts or other protected credential mechanisms.
Detection
- Search SYSVOL for Groups.xml, Services.xml, ScheduledTasks.xml and similar files containing cpassword attributes.
- Alert on access to GPP preference XML files by accounts or hosts that do not normally read them.
- Monitor authentication events for privileged accounts using credentials that were previously stored in GPP.
- Review GPO backups and version history for historical password entries that may still be recoverable.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2014-1812 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Microsoft Windows Group Policy Preferences Password Privilege Escalation Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://blogs.technet.com/b/srd/archive/2014/05/13/ms14-025-an-update-for-group-policy-preferences.aspx | Third Party Advisory |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-025 | PatchVendor Advisory |
| http://blogs.technet.com/b/srd/archive/2014/05/13/ms14-025-an-update-for-group-policy-preferences.aspx | Third Party Advisory |
| https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-025 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-1812 | US Government Resource |
Track CVE-2014-1812 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-1812), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.