2.1

CVE-2020-1464

Warnung
Exploit

Windows Spoofing Vulnerability

A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files.
In an attack scenario, an attacker could bypass security features intended to prevent improperly signed files from being loaded.
The update addresses the vulnerability by correcting how Windows validates file signatures.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 10 1507 Version -
Microsoft ≫ Windows 10 1607 Version -
Microsoft ≫ Windows 10 1709 Version -
Microsoft ≫ Windows 10 1803 Version -
Microsoft ≫ Windows 10 1809 Version -
Microsoft ≫ Windows 10 1903 Version -
Microsoft ≫ Windows 10 1909 Version -
Microsoft ≫ Windows 10 2004 Version -
Microsoft ≫ Windows 7 Version - Update sp1
Microsoft ≫ Windows 8.1 Version -
Microsoft ≫ Windows Rt 8.1 Version -
Microsoft ≫ Windows Server 2008 Version - Update sp2
Microsoft ≫ Windows Server 2008 Version r2 Update sp1 HwPlatform x64

03.11.2021: CISA Known Exploited Vulnerabilities (KEV) Catalog

Microsoft Windows Spoofing Vulnerability

Schwachstelle

Microsoft Windows contains a spoofing vulnerability when Windows incorrectly validates file signatures, allowing an attacker to bypass security features and load improperly signed files.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 41.13% 0.985
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:N/I:P/A:N
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Microsoft 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-347 Improper Verification of Cryptographic Signature

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

https://blog.virustotal.com/2019/01/distribution-of-malicious-jar-appended.html
Third Party Advisory
https://krebsonsecurity.com/2020/08/microsoft-put-off-fixing-zero-day-for-2-years/
Third Party Advisory
Issue Tracking
https://medium.com/%40TalBeerySec/glueball-the-story-of-cve-2020-1464-50091a1f98bd
Third Party Advisory
Exploit
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1464
Patch
Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-1464
US Government Resource