Disclosure summary
The Authenticode Signature Verification function in Microsoft Windows (WinVerifyTrust) does not properly validate the digest of a signed portable executable (PE) file, which allows user-assisted remote attackers to execute code.
CISA remediation guidance
Apply updates per vendor instructions.
Original records & references
PUBLISHED 2022-06-08T00:00:00-04:00
MODIFIED 2022-06-08T00:00:00-04:00
INGESTED 2026-10-06T11:42:58-04:00