Executive brief
proCertum SmartSign is an application used for creating and verifying electronic signatures on digital documents. A security flaw allows an attacker to create a malicious document that, when opened by a user, automatically executes a local file or opens an arbitrary website. This could lead to unauthorized software execution or phishing attacks on the victim's computer.
Technical details
The vulnerability is classified as External Control of File Name or Path (CWE-73). proCertum SmartSign opens the Certificate Practice Statement (CPS) URI embedded in a certificate without performing schema validation. An attacker can craft a certificate with a CPS URI pointing to a local executable file or a malicious URL and use it to sign a document. When a victim opens this document within the application, the software triggers the URI, leading to local code execution or the opening of a web browser to an attacker-controlled site. The issue is resolved in version 9.4.3.90.
Affected products
- Asseco proCertum SmartSign All versions below 9.4.3.90
Timeline
- 2026-07-27: advisory
- 2026-07-27: disclosed
- 2026-07-27: patched: Fixed in version 9.4.3.90