GPP Attacks

Overview

  • Group Policy Preferences allowed admins to create policies using embedded credentials

  • These credentials were encrypted and placed in a cPassword

  • The key was accidentally released

  • Patched in MS14-025, but doesn't prevent previous uses

Last updated