Microsoft Windows Authenticode Signature Verification Remote Code Execution Vulnerability
Microsoft · Windows
Date added (CISA)
2022-06-08
Remediation due
2022-06-22
Known ransomware use
Not indicated
Remediation priority
P2 — past CISA due date
Description
The Authenticode Signature Verification function in Microsoft Windows (WinVerifyTrust) does not properly validate the digest of a signed portable executable (PE) file, which allows user-assisted remote attackers to execute code.