Executive brief
A remote code execution vulnerability exists in the WinVerifyTrust function's handling of Windows Authenticode signature verification for Portable Executable (PE) files. An attacker can modify a signed executable to include malicious code in unverified portions of the file without invalidating the digital signature. Successful exploitation requires a user to run or install a specially crafted, signed PE file, potentially granting the attacker complete control over the affected system.
Affected products
- Microsoft Windows 10 All currently supported versions
- Microsoft Windows 11 All currently supported versions
- Microsoft Windows Server 2008 SP2, R2 SP1
- Microsoft Windows 7 SP1
- Microsoft Windows 8.1
- Microsoft Windows Server 2012 R2
- Microsoft Windows Server 2016
- Microsoft Windows Server 2019
- Microsoft Windows Server 2022
Timeline
- 2013-12-10: disclosed: Original publication of MS13-098 and CVE-2013-3900
- 2022-01-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-01-10: advisory: Republished by Microsoft to update supported Windows versions and configuration guidance