CVE-2012-0151
Microsoft Windows Authenticode Signature Verification Remote Code Execution Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 22 June 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
The Authenticode Signature Verification function in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly validate the digest of a signed portable executable (PE) file, which allows user-assisted remote attackers to execute arbitrary code via a modified file with additional content, aka "WinVerifyTrust Signature Validation Vulnerability."
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 88.78% probability · 100th percentile
- CISA KEV
- Listed 8 June 2022 · due 22 June 2022
- Weakness
- CWE-20
- Affected
- microsoft/windows 7 · microsoft/windows server 2003 · microsoft/windows server 2008 · microsoft/windows vista · microsoft/windows xp
- Source
- secure@microsoft.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2012-0151
References
- http://osvdb.org/81135Broken Link
- http://secunia.com/advisories/48581Broken Link
- http://www.securitytracker.com/id?1026906Broken Link, Third Party Advisory, VDB Entry
- http://www.us-cert.gov/cas/techalerts/TA12-101A.htmlThird Party Advisory, US Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-024Patch, Vendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15594Broken Link
- http://osvdb.org/81135Broken Link
- http://secunia.com/advisories/48581Broken Link
- http://www.securitytracker.com/id?1026906Broken Link, Third Party Advisory, VDB Entry
- http://www.us-cert.gov/cas/techalerts/TA12-101A.htmlThird Party Advisory, US Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2012/ms12-024Patch, Vendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15594Broken Link
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2012-0151US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.