CVE-2013-3900
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2013-3900: Microsoft republished this vulnerability to update the Security Updates table and confirm the availability of the EnableCertPaddingCheck feature in all current Windows 10 and 11 versions. This vulnerability, first identified in 2013, allows remote code execution via manipulated Windows Authenticode signed PE files, potentially granting attackers full system control. Microsoft does not plan to enforce stricter verification behavior as a default, but users must enable the feature via reg key setting. Users with fewer account privileges may be less impacted. Exploitation requires a specially crafted, signed PE file to be run or installed.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Windows Server 2008
- Microsoft Windows 7
- Microsoft Windows 8.1
- Microsoft Windows Server 2012
- Microsoft Windows Server 2016
Affected Vendors
- Microsoft