MS14-025: Vulnerability in Group Policy Preferences Could Allow Elevation of Privilege (2962486)

high Nessus Plugin ID 73984

Synopsis

The remote Windows host is potentially affected by a privilege elevation vulnerability.

Description

The remote Windows host is potentially affected by a vulnerability in the way that Active Directory distributes passwords that are configured using Group Policy preferences. This could allow a remote attacker to retrieve and decrypt passwords stored with Group Policy preferences.

The following group policy preferences extensions are affected :

- Local user and group
- Mapped drives
- Services
- Scheduled tasks (Uplevel)
- Scheduled tasks (Downlevel)
- Immediate tasks (Uplevel)
- Immediate tasks (Downlevel)
- Data sources

Note that this update does not remove any existing Group Policy Objects (GPOs). GPOs using the mentioned group policy preferences will need to be updated to not distribute passwords.

Solution

Microsoft has released a set of patches for Windows Vista, 2008, 7, 2008 R2, 8, 2012, 8.1, and 2012 R2.

See Also

https://docs.microsoft.com/en-us/security-updates/SecurityBulletins/2014/ms14-025

Plugin Details

Severity: High

ID: 73984

File Name: smb_nt_ms14-025.nasl

Version: 1.13

Type: local

Agent: windows

Published: 5/14/2014

Updated: 11/30/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.7

CVSS v2

Risk Factor: High

Base Score: 9

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2014-1812

Vulnerability Information

CPE: cpe:/o:microsoft:windows

Required KB Items: SMB/MS_Bulletin_Checks/Possible

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 5/13/2014

Vulnerability Publication Date: 5/13/2014

CISA Known Exploited Vulnerability Due Dates: 5/3/2022

Exploitable With

CANVAS (CANVAS)

Core Impact

Reference Information

CVE: CVE-2014-1812

BID: 67275

IAVA: 2014-A-0071

MSFT: MS14-025

MSKB: 2928120, 2961899