CVE-2012-0151highunder attackCWE-20

CVE-2012-0151

Published · Updated

73Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA.

ssvc Actcvss 7.8epss 88%
from disclosure to weapon
Published on NVDApr 10
CISA KEV+3711d
exploitation probability
88%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
Action required by CISAfederal deadline: 2022-06-22

Apply updates per vendor instructions.

In short

Windows fails to properly check if executable files have been tampered with after being signed, allowing attackers to add malicious code to signed programs without detection. This means a legitimate-looking file could contain hidden harmful content.

Technical detail

The WinVerifyTrust function improperly validates the cryptographic digest of signed PE files, allowing attackers to append arbitrary content without invalidating the signature. Exploitation requires user interaction (file execution) and affects multiple Windows versions across XP through Windows 8, with impact ranging from arbitrary code execution in the security context of the executing user.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

The Authenticode Signature Verification function in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly validate the digest of a signed portable executable (PE) file, which allows user-assisted remote attackers to execute arbitrary code via a modified file with additional content, aka "WinVerifyTrust Signature Validation Vulnerability."
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
n/a · n/a