Junglewise Threat Intelligence

CVE-2013-3900: Microsoft WinVerifyTrust function Remote Code Execution

CVE-2013-3900 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-01-10

Technologies: Microsoft Windows Server 2008, Microsoft Windows 8.1, Microsoft Windows Server 2022, Microsoft Windows Server 2019, Microsoft Windows Server 2016, Microsoft Windows 7, Microsoft Windows Server 2012, Microsoft Windows 11, Microsoft Windows 10. Vendors: Microsoft.

Executive brief

A remote code execution vulnerability exists in the WinVerifyTrust function's handling of Windows Authenticode signature verification for Portable Executable (PE) files. An attacker can modify a signed executable to include malicious code in unverified portions of the file without invalidating the digital signature. Successful exploitation requires a user to run or install a specially crafted, signed PE file, potentially granting the attacker complete control over the affected system.

Affected products

  • Microsoft Windows 10 All currently supported versions
  • Microsoft Windows 11 All currently supported versions
  • Microsoft Windows Server 2008 SP2, R2 SP1
  • Microsoft Windows 7 SP1
  • Microsoft Windows 8.1
  • Microsoft Windows Server 2012 R2
  • Microsoft Windows Server 2016
  • Microsoft Windows Server 2019
  • Microsoft Windows Server 2022

Timeline

  • 2013-12-10: disclosed: Original publication of MS13-098 and CVE-2013-3900
  • 2022-01-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-01-10: advisory: Republished by Microsoft to update supported Windows versions and configuration guidance