CVE-2013-3900CISA KEV
Microsoft WinVerifyTrust function Remote Code Execution
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
A remote code execution vulnerability exists in the way that the WinVerifyTrust function handles Windows Authenticode signature verification for PE files.
- Product
- WinVerifyTrust function
- Added to KEV
- 10 Jan 2022
- Federal remediation due
- 10 Jul 2022
- Known ransomware use
- Not reported