Executive brief
The Authenticode Signature Verification function (WinVerifyTrust) in Microsoft Windows fails to properly validate the digest of signed portable executable (PE) files. A remote attacker can exploit this by tricking a user into opening a modified file with additional malicious content, leading to arbitrary code execution.
Affected products
- Microsoft Windows XP SP2, SP3
- Microsoft Windows Server 2003 SP2
- Microsoft Windows Vista SP2
- Microsoft Windows Server 2008 SP2, R2, R2 SP1
- Microsoft Windows 7 Gold, SP1
- Microsoft Windows 8 Consumer Preview Consumer Preview
Timeline
- 2012-04-10: patched: Microsoft released security bulletin MS12-024 to address the vulnerability.
- 2022-06-08: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.
- 2022-06-08: disclosed: NVD publication date.