Microsoft Windows Group Policy Preferences Password Privilege Escalation Vulnerability
Microsoft Windows Vista SP2, Windows Server 2008 SP2 및 R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold 및 R2의 Group Policy 구현은 암호 배포를 올바르게 처리하지 않습니다. 이로 인해 원격 인증 사용자가 SYSVOL 공유에 대한 접근을 활용하여 민감한 자격 증명 정보를 입수하고, 그 결과 권한을 획득할 수 있습니다. 이는 2014년 5월 실제로 악용되었으며, 이 취약점은 "Group Policy Preferences Password Elevation of Privilege Vulnerability"라고도 합니다.
Microsoft Windows Vista SP2, Windows Server 2008 SP2 및 R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold 및 R2의 Group Policy 구현은 암호 배포를 올바르게 처리하지 않습니다. 이로 인해 원격 인증 사용자가 SYSVOL 공유에 대한 접근을 활용하여 민감한 자격 증명 정보를 입수하고, 그 결과 권한을 획득할 수 있습니다. 이는 2014년 5월 실제로 악용되었으며, 이 취약점은 "Group Policy Preferences Password Elevation of Privilege Vulnerability"라고도 합니다.
한국어 설명은 영문 원문을 기준으로 제공됩니다. 제품명·버전·보안 식별자는 아래 원문과 함께 확인할 수 있습니다.
영문 원문 보기
The Group Policy implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does not properly handle distribution of passwords, which allows remote authenticated users to obtain sensitive credential information and consequently gain privileges by leveraging access to the SYSVOL share, as exploited in the wild in May 2014, aka "Group Policy Preferences Password Elevation of Privilege Vulnerability."