Junglewise Threat Intelligence

CVE-2020-1464: Microsoft Windows Spoofing Vulnerability

CVE-2020-1464 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2021-11-03

Technologies: Microsoft Windows Server 2008, Microsoft Windows, Microsoft Windows 8.1, Microsoft Windows Server 2016, Microsoft Windows Server 2019, Microsoft Windows 10, Microsoft Windows 7, Microsoft Windows Server 2012, Microsoft Windows Rt 8.1. Vendors: Microsoft.

Executive brief

A spoofing vulnerability exists in Microsoft Windows due to incorrect validation of file signatures. An attacker can exploit this to bypass security features and load improperly signed files, effectively circumventing protections intended to verify software authenticity.

Affected products

  • Microsoft Windows 10 1507, 1607, 1709, 1803, 1809, 1903, 1909, 2004
  • Microsoft Windows 7 SP1
  • Microsoft Windows 8.1
  • Microsoft Windows RT 8.1
  • Microsoft Windows Server 2008 SP2, R2 SP1
  • Microsoft Windows Server 2012 R2
  • Microsoft Windows Server 2016 1903, 1909, 2004
  • Microsoft Windows Server 2019

Timeline

  • 2019-01: other: Earliest public discussion of related malicious JAR distribution techniques.
  • 2020-08-11: patched: Microsoft released security updates to address the vulnerability.
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2021-11-03: disclosed

Related threats