CVE-2012-0151
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA.
Apply updates per vendor instructions.
Windows fails to properly check if executable files have been tampered with after being signed, allowing attackers to add malicious code to signed programs without detection. This means a legitimate-looking file could contain hidden harmful content.
The WinVerifyTrust function improperly validates the cryptographic digest of signed PE files, allowing attackers to append arbitrary content without invalidating the signature. Exploitation requires user interaction (file execution) and affects multiple Windows versions across XP through Windows 8, with impact ranging from arbitrary code execution in the security context of the executing user.
The full analysis of this CVE is available in Portuguese →