CVE-2012-0151CISA KEV
Microsoft Windows Authenticode Signature Verification Remote Code Execution Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
The Authenticode Signature Verification function in Microsoft Windows (WinVerifyTrust) does not properly validate the digest of a signed portable executable (PE) file, which allows user-assisted remote attackers to execute code.
- Product
- Windows
- Added to KEV
- 8 Jun 2022
- Federal remediation due
- 22 Jun 2022
- Known ransomware use
- Not reported