The vulnerability could allow an attacker to upgrade unprivileged domain user account privileges to those of a domain administrator account.
The update was released on Tuesday, according to information available on the company's Security Response Center website.
Microsoft said it was aware of limited, targeted attacks that aimed to exploit the security issue at the time it issued the update.
On Tuesday, November 18, 2014, at approximately 10 a.m. PST, we will release an out-of-band security update to address a vulnerability in Windows.
We strongly encourage customers to apply this update as soon as possible, following the directions in the security bulletin.
Written with inputs from Reuters
Catch the latest from the Consumer Electronics Show on Gadgets 360, at our CES 2026 hub.