CVE-2023-40012
As a result, a malicious user could produce a "signed" PE file that uthenticode would verify and consider valid using an X.509 certificate that isn't entitled to produce code signatures (e.g., a SSL certificate).
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.25%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
uthenticode is a small cross-platform library for partially verifying Authenticode digital signatures. Versions of uthenticode prior to the 2.x series did not check Extended Key Usages in certificates, in violation of the Authenticode X.509 certificate profile. As a result, a malicious user could produce a "signed" PE file that uthenticode would verify and consider valid using an X.509 certificate that isn't entitled to produce code signatures (e.g., a SSL certificate). By design, uthenticode does not perform full-chain validation. However, the absence of EKU validation was an unintended oversight. The 2.0.0 release series includes EKU checks. There are no workarounds to this vulnerability.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.25% probability · 16th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-325, CWE-347
- Affected
- trailofbits/uthenticode
- Source
- security-advisories@github.com
References
- https://github.com/trailofbits/uthenticode/commit/caeb1eb62412605f71bd96ce9bb9420644b6db53Patch
- https://github.com/trailofbits/uthenticode/pull/78Patch
- https://github.com/trailofbits/uthenticode/security/advisories/GHSA-gm2f-j4rj-6xqjVendor Advisory
- https://github.com/trailofbits/uthenticode/commit/caeb1eb62412605f71bd96ce9bb9420644b6db53Patch
- https://github.com/trailofbits/uthenticode/pull/78Patch
- https://github.com/trailofbits/uthenticode/security/advisories/GHSA-gm2f-j4rj-6xqjVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.