• Home
  • About 404TS
  • Contact

404 Tech Support

Where IT Help is Found

  • Articles
    • Code
    • Entertainment
    • Going Green
    • Hardware, Gadgets, and Products
    • Management
    • Network
    • News
    • Operating Systems
    • Security and Privacy
    • Software
    • System Administration
    • Talking Points
    • Tech Solutions
    • Web
    • Webmaster
  • Reviews
  • Media
    • Infographics
    • Videos
  • Tech Events
  • Tools
    • How do I find my IP address?
    • Browser and plugin tests
  • Get a Technical Consultation
You are here: Home / Articles / System Administration / MS14-025 changes Group Policies Preferences

MS14-025 changes Group Policies Preferences

2014-05-15 by Jason

An update released with this month’s Patch Tuesday updated the behavior of Group Policy Preferences. The change is a security fix in nature but mostly keeps people from setting themselves up for failure.

The problem that the update addresses comes from different Group Policy Preferences that allow you to store credentials. GPPs could be used to create or modify local user accounts, map network drives, or other settings that could be run as a specific user account.

gpp

If an attacker is able to get access to the SYSVOL share (which is open to all authenticated users, so a malicious or spear phished employee will have access to it) and obtain the AES encryption key used to encrypt/decrypt passwords set with GPP (which we document on MSDN), the attacker will be able to obtain the credentials set with GPP.

Basically, one compromised domain user could result in all of those account credentials used in Group Policy Preferences to be easily obtained. Unfortunately, some organizations might use the domain admin credentials in a GPP, resulting in the whole organization being compromised. Even worse, it’s a fairly simple and common attack.

Microsoft has observed that Group Policy Preferences abuse is one of the most common tactics used by attackers to elevate permissions in a domain. Multiple toolkits used by attackers such as Metasploit and PowerSploit provide easy to use methods for retrieving and decrypting GPP passwords.

As  a result, Microsoft released an update to address this. Any existing GPOs with account credentials will not be able to be modified and new GPOs with account credentials will not be able to be created. The GPOs are not being automatically disabled as that could seriously affect an organization’s operation.

Along with the update, Microsoft has provided two PowerShell scripts. One is an alternative to set local administrator passwords on remote systems. The second script can be run on a domain controller to detect GPOs that are using account credentials in Group Policy Preferences.

To read more about this update and obtain a copy of those scripts, see these pages for more details:

  • Microsoft Security Research and Defense Blog
  • KB 2962486

Filed Under: System Administration

Trending

  • Ask 404TS: Why are photos from a digital camera always in a folder called DCIM?
    In Tech Solutions
  • Dell’s WiGig Wireless dock with the Latitude 6430u Ultrabook
    In Hardware, Gadgets, and Products
  • Enable Windows 10 firewall to install fonts
    In Tech Solutions

Latest Media Posts

Find Out Where To Download SNES ROMs

Find Out Where To Download SNES ROMs

Multifunctional Video Conversion Tools – Wondershare Video Converter

Multifunctional Video Conversion Tools – Wondershare Video Converter

  • Popular
  • Latest
  • Today Week Month All
  • Access to the resource [servershare] has been disallowed Access to the resource [servershare] has been disallowed
  • Read the Event Logs on Windows Server Core Read the Event Logs on Windows Server Core
  • Increase IIS Private Memory Limit to improve WSUS availability Increase IIS Private Memory Limit to improve WSUS availability
  • How to ‘Unblock’ multiple files at a time with PowerShell How to 'Unblock' multiple files at a time with PowerShell
  • Setup your DFS namespace with DNS for compatibility in a mixed environment Setup your DFS namespace with DNS for compatibility in a mixed environment
  • How Virtual Reality Supports Mental Health Therapy How Virtual Reality Supports Mental Health Therapy
  • Key Strategies of Successful Coin Listing on Exchange Key Strategies of Successful Coin Listing on Exchange
  • Keeping Your Mac Healthy: A Comprehensive Guide to Maintenance and Troubleshooting Keeping Your Mac Healthy: A Comprehensive Guide to Maintenance and Troubleshooting
  • Making Distributed Software Development Work: Strategies and Best Practices for Managing Remote Teams Making Distributed Software Development Work: Strategies and Best Practices for Managing Remote Teams
  • customer contactless payment for drink with mobile phon at cafe counter bar,seller coffee shop accept payment by mobile.new normal lifestyle concept The Latest Innovations In Payment Technology
Ajax spinner

Elevator Pitch

404 Tech Support documents solutions to IT problems, shares worthwhile software and websites, and reviews hardware, consumer electronics, and technology-related books.

Subscribe to 404TS articles by email.

Recent Posts

  • How Virtual Reality Supports Mental Health Therapy
  • Key Strategies of Successful Coin Listing on Exchange
  • Keeping Your Mac Healthy: A Comprehensive Guide to Maintenance and Troubleshooting

Search

FTC Disclaimer

404TechSupport is an Amazon.com affiliate; when you click on an Amazon link from 404TS, the site gets a cut of the proceeds from whatever you buy. This site also uses Skimlinks for smart monetization of other affiliate links.
Use of this site requires displaying and viewing ads as they are presented.

Copyright © 2025 · Magazine Pro Theme on Genesis Framework · WordPress · Log in