CISA Known Exploited Vulnerability

CVE-2013-3900

Microsoft · WinVerifyTrust function

Microsoft WinVerifyTrust function Remote Code Execution

Date added
BOD 22-01 due date
CWE CWE-20
Ransomware Unknown

CISA description

A remote code execution vulnerability exists in the way that the WinVerifyTrust function handles Windows Authenticode signature verification for PE files.

Required action

Apply updates per vendor instructions.