In 2014, Microsoft published a patch to resolve an issue that caused administrative credentials to be stored insecurely in a location reachable by any user on the Windows domain. Many administrators patched the flaw but failed to read the release notes instructing them on how to remove the already saved credentials. This flaw was tracked as MS14-025. Answer the following questions needed to take advantage of this flaw: Where did group policy store these passwords? Use of a static AES key for all users made this system weak. What was the actual key used? Are there tools available to decrypt these passwords? If so, name at least one.