CISA Known Exploited Vulnerability

CVE-2020-1464

Microsoft · Windows

Microsoft Windows Spoofing Vulnerability

Date added
BOD 22-01 due date
CWE CWE-347
Ransomware Unknown

CISA description

Microsoft Windows contains a spoofing vulnerability when Windows incorrectly validates file signatures, allowing an attacker to bypass security features and load improperly signed files.

Required action

Apply updates per vendor instructions.