CVE-2020-1464
published 2020-08-17CVE-2020-1464: A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass…
PriorityP279medium5.5CVSS 3.1
AVLACLPRLUINSUCNIHAN
KEVITW
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
41.13%
98.5th percentile
A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files.
In an attack scenario, an attacker could bypass security features intended to prevent improperly signed files from being loaded.
The update addresses the vulnerability by correcting how Windows validates file signatures.
Affected
41 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_version_1507 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1607 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1709 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1709_for_32-bit_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1803 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1809 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1903_for_32-bit_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1903_for_arm64-based_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1903_for_x64-based_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1909 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_2004 | >= 10.0.0 < publication | publication |
| microsoft | windows_7 | >= 6.1.0 < publication | publication |
| microsoft | windows_7_service_pack_1 | >= 6.1.0 < publication | publication |
| microsoft | windows_8.1 | >= 6.3.0 < publication | publication |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.0.0 < publication | publication |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.0 < publication | publication |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.0 < publication | publication |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.0 < publication | publication |
| microsoft | windows_server_2012_r2 | >= 6.3.0 < publication | publication |
| microsoft | windows_server_2016 | >= 10.0.0 < publication | publication |
| microsoft | windows_server_2019 | >= 10.0.0 < publication | publication |
| microsoft | windows_server_version_2004 | >= 10.0.0 < publication | publication |
| msrc | windows_10 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect MSI/JAR polyglot files: scan for files with a valid Authenticode signature on an MSI that also contain appended JAR content — the exploit works by appending a malicious JAR to a signed MSI and renaming the result with a .jar extension while retaining a valid Windows signature. ↗
- →Flag any file presenting as .jar that carries a valid Windows Authenticode/code-signing signature, as legitimate JAR files do not carry Windows digital signatures — this is a strong indicator of GlueBall-style abuse of CVE-2020-1464. ↗
- →This vulnerability (dubbed 'GlueBall') was actively exploited in the wild since at least August 2018 — threat hunting should cover a two-year retrospective window for MSI+JAR polyglot files. ↗
- →Use YARA rules or polyglot-aware file-format detection to identify files that simultaneously conform to both MSI and JAR format specifications, as standard AV routing may only inspect one format and miss the malicious payload. ↗
- ·The attack is not limited to JAR files — the weakness applies to any content appended to a signed MSI; JAR is highlighted as a particularly dangerous vector but other formats may also be abused. ↗
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
vulncheck7.8HIGH
cisa5.5MEDIUM
vendor_msrc5.3MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-75g4-7255-wxgc: A spoofing vulnerability exists when Windows incorrectly validates file signatures, aka 'Windows Spoofing Vulnerability'
ghsa_unreviewed·2022-05-24
CVE-2020-1464 [LOW] CWE-347 GHSA-75g4-7255-wxgc: A spoofing vulnerability exists when Windows incorrectly validates file signatures, aka 'Windows Spoofing Vulnerability'
A spoofing vulnerability exists when Windows incorrectly validates file signatures, aka 'Windows Spoofing Vulnerability'.
VulnCheck
Microsoft Windows Spoofing Vulnerability
vulncheck·2020·CVSS 7.8
CVE-2020-1464 [HIGH] CWE-347 Microsoft Windows Spoofing Vulnerability
Microsoft Windows Spoofing Vulnerability
Microsoft Windows contains a spoofing vulnerability when Windows incorrectly validates file signatures, allowing an attacker to bypass security features and load improperly signed files.
Affected: Microsoft Windows
Required Action: Apply updates per vendor instructions.
Exploitation References: https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2020-Aug; https://cisa.gov/news-events/alerts/2020/08/11/microsoft-addresses-rce-and-spoofing-vulnerabilities-under-active; https://twitter.com/Securityinbits/status/1271406138588708866; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Remediation Due: 2022-05-03
CISA
Microsoft Windows Spoofing Vulnerability
cisa·2021-11-03·CVSS 5.5
CVE-2020-1464 [MEDIUM] CWE-347 Microsoft Windows Spoofing Vulnerability
Vulnerability: Microsoft Windows Spoofing Vulnerability
Affected: Microsoft Windows
Microsoft Windows contains a spoofing vulnerability when Windows incorrectly validates file signatures, allowing an attacker to bypass security features and load improperly signed files.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2020-1464
Remediation Due Date: 2022-05-03
Microsoft
Windows Spoofing Vulnerability
vendor_msrc·2020-08-11·CVSS 5.3
CVE-2020-1464 [HIGH] Windows Spoofing Vulnerability
Windows Spoofing Vulnerability
Description: A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files.
In an attack scenario, an attacker could bypass security features intended to prevent improperly signed files from being loaded.
The update addresses the vulnerability by correcting how Windows validates file signatures.
Microsoft Windows: Microsoft Windows
Microsoft: Microsoft
Impact: Spoofing
Exploit Status: Publicly Disclosed:Yes;Exploited:Yes;Latest Software Release:Exploitation Detected;Older Software Release:Exploitation Detected;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4571709
Reference: htt
No detection rules found.
No public exploits indexed.
Qualys
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
blogs_qualys·2022-02-23
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
#### Table of Contents
- Situation
- Directive Scope
- CISA Catalog of Known Exploited Vulnerabilities
- Detect CISA Vulnerabilities Using Qualys VMDR
- CISA Exploited RTI
- Detailed Operational Dashboard
- Remediation
- Federal Enterprises and Agencies Can Act Now
- Summary
- Getting Started
CISA released a directive in November 2021, recommending urgent and prioritized remediation of actively exploited vulnerabilities. Both government agencies and corporations should heed this advice. This blog outlines how Qualys Vulnerability Management, Detection & Response can be used by any organization to respond to this directive efficiently and effectively.
## Situation
Last November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directiv
Tenable
One Year Later: What Can We Learn from Zerologon?
blogs_tenable·2021-08-11
One Year Later: What Can We Learn from Zerologon?
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Securelist
IT threat evolution Q3 2020. Non-mobile statistics
blogs_securelist·2020-11-20
IT threat evolution Q3 2020. Non-mobile statistics
Table of Contents
Quarterly figures
Financial threats
Financial threat statistics
Attack geography
Ransomware programs
Quarterly trends and highlights
Number of new modifications
Number of users attacked by ransomware Trojans
Attack geography
Miners
Number of new modifications
Number of users attacked by miners
Attack geography
Vulnerable applications used by cybercriminals during cyberattacks
Attacks on macOS
Threat geography
IoT attacks
IoT threat statistics
Attacks via web resources
Countries that are sources of web-based attacks: Top 10
Countries where users faced the greatest risk of online infection
Local threats
Countries where users faced the highest risk of local infection
Authors
Victor Chebyshev
Fedor Sinitsyn
Denis Parinov
Oleg Kupreev
Evgeny Lopati
Securelist
IT threat evolution Q3 2020. Non-mobile statistics
blogs_securelist·2020-11-20
IT threat evolution Q3 2020. Non-mobile statistics
Table of Contents
- Quarterly figures
- Financial threats
- Ransomware programs
- Miners
- Vulnerable applications used by cybercriminals during cyberattacks
- Attacks on macOS
- IoT attacks
- Attacks via web resources
- Local threats
Authors
- Victor Chebyshev
- Fedor Sinitsyn
- Denis Parinov
- Oleg Kupreev
- Evgeny Lopatin
- Alexey Kulaev
- Alexander Kolesnikov
These statistics are based on detection verdicts of Kaspersky products received from users who consented to provide statistical data.
## Quarterly figures
According to Kaspersky Security Network, in Q3:
- Kaspersky solutions blocked 1,416,295,227 attacks launched from online resources across the globe.
- 456,573,467 unique URLs were recognized as malicious by Web Anti-Virus components.
- Attempts to run malware for stealing
Krebs
Microsoft Put Off Fixing Zero Day for 2 Years
blogs_krebs·2020-08-17·CVSS 7.8
CVE-2020-1464 [HIGH] Microsoft Put Off Fixing Zero Day for 2 Years
A security flaw in the way Microsoft Windows guards users against malicious files was actively exploited in malware attacks for two years before last week, when Microsoft finally issued a software update to correct the problem.
One of the 120 security holes Microsoft fixed on Aug. 11’s Patch Tuesday was CVE-2020-1464 , a problem with the way every supported version of Windows validates digital signatures for computer programs.
Code signing is the method of using a certificate-based digital signature to sign executable files and scripts in order to verify the author’s identity and ensure that the code has not been changed or corrupted since it was signed by the author.
Microsoft said an attacker could use this “spoofing vulnerability” to bypass security features intended to prevent impro
Krebs
Microsoft Put Off Fixing Zero Day for 2 Years
blogs_krebs·2020-08-17·CVSS 7.8
CVE-2020-1464 [HIGH] Microsoft Put Off Fixing Zero Day for 2 Years
A security flaw in the way Microsoft Windows guards users against malicious files was actively exploited in malware attacks for two years before last week, when Microsoft finally issued a software update to correct the problem.
One of the 120 security holes Microsoft fixed on Aug. 11’s Patch Tuesday was CVE-2020-1464, a problem with the way every supported version of Windows validates digital signatures for computer programs.
Code signing is the method of using a certificate-based digital signature to sign executable files and scripts in order to verify the author’s identity and ensure that the code has not been changed or corrupted since it was signed by the author.
Microsoft said an attacker could use this “spoofing vulnerability” to bypass security features intended to prevent improp
Trendmicro
Patch Tuesday: Fixes for Important Vulnerabilities
blogs_trendmicro·2020-08-11·CVSS 7.8
[HIGH] Patch Tuesday: Fixes for Important Vulnerabilities
Exploits & Vulnerabilities
## Patch Tuesday: Fixes for Important Vulnerabilities
The August batch of Patch Tuesday updates includes 120 updates for the Microsoft suite, with 17 fixes rated as Critical, and the remaining 103 ranked as Important. ZDI disclosed 11 flaws, five of which are rated critical bugs.
By: Trend Micro Aug 11, 2020 Read time: ( words)
Save to Folio
Update on 19/08/2020 09:55AM PHT: Added rules for Trend Micro Deep Security.
The August batch of Patch Tuesday updates includes 120 updates for the Microsoft suite, with 17 fixes rated as Critical, and the remaining 103 ranked as Important. CVE-2020-1380 is a critical Internet Explorer (IE) vulnerability that can be abused for remote code execution (RCE), while CVE-2020-1464 is a Windows 10 security gap that can be used
Trendmicro
Patch Tuesday: Fixes for Important Vulnerabilities
blogs_trendmicro·2020-08-11·CVSS 7.8
[HIGH] Patch Tuesday: Fixes for Important Vulnerabilities
Exploits & Vulnerabilities
## Patch Tuesday: Fixes for Important Vulnerabilities
The August batch of Patch Tuesday updates includes 120 updates for the Microsoft suite, with 17 fixes rated as Critical, and the remaining 103 ranked as Important. ZDI disclosed 11 flaws, five of which are rated critical bugs.
By: Trend Micro 2020/08/11 Read time: ( words)
Save to Folio
Update on 08/19/2020 09:55AM PHT: Added rules for Trend Micro Deep Security.
The August batch of Patch Tuesday updates includes 120 updates for the Microsoft suite, with 17 fixes rated as Critical, and the remaining 103 ranked as Important. CVE-2020-1380 is a critical Internet Explorer (IE) vulnerability that can be abused for remote code execution (RCE), while CVE-2020-1464 is a Windows 10 security gap that can be used f
Krebs
Microsoft Patch Tuesday, August 2020 Edition
blogs_krebs·2020-08-11·CVSS 7.8
[HIGH] Microsoft Patch Tuesday, August 2020 Edition
Microsoft today released updates to plug at least 120 security holes in its Windows operating systems and supported software, including two newly discovered vulnerabilities that are actively being exploited. Yes, good people of the Windows world, it’s time once again to backup and patch up!
At least 17 of the bugs squashed in August’s patch batch address vulnerabilities Microsoft rates as “critical,” meaning they can be exploited by miscreants or malware to gain complete, remote control over an affected system with little or no help from users. This is the sixth month in a row Microsoft has shipped fixes for more than 100 flaws in its products.
The most concerning of these appears to be CVE-2020-1380 , which is a weaknesses in Internet Explorer that could result in system compromise just
Trendmicro
Patch Tuesday: Fixes for Important Vulnerabilities
blogs_trendmicro·2020-08-11·CVSS 7.8
[HIGH] Patch Tuesday: Fixes for Important Vulnerabilities
Exploits & Vulnerabilities
# Patch Tuesday: Fixes for Important Vulnerabilities
The August batch of Patch Tuesday updates includes 120 updates for the Microsoft suite, with 17 fixes rated as Critical, and the remaining 103 ranked as Important. ZDI disclosed 11 flaws, five of which are rated critical bugs.
By: Trend Micro
2020/08/11
Read time: ( words)
Save to Folio
Update on 08/19/2020 09:55AM PHT: Added rules for Trend Micro Deep Security.
The August batch of Patch Tuesday updates includes 120 updates for the Microsoft suite, with 17 fixes rated as Critical, and the remaining 103 ranked as Important. CVE-2020-1380 is a critical Internet Explorer (IE) vulnerability that can be abused for remote code execution (RCE), while CVE-2020-1464 is a Windows 10 security gap that can be used f
Qualys
August 2020 Patch Tuesday – 120 Vulnerabilities, 17 Critical, Media Foundation, Windows Codecs, Workstation, Adobe | Qualys
blogs_qualys·2020-08-11·CVSS 7.8
[HIGH] August 2020 Patch Tuesday – 120 Vulnerabilities, 17 Critical, Media Foundation, Windows Codecs, Workstation, Adobe | Qualys
This month’s Microsoft Patch Tuesday addresses 120 vulnerabilities with 17 of them labeled as Critical. The 17 Critical vulnerabilities cover Media Foundation, .NET Framework, Browsers, Scripting Engines, Office, Outlook, Windows Codecs and several other workstation vulnerabilities. Adobe released patches today for Acrobat/Reader, and Lightroom.
### Workstation Patches
Today’s patch Tuesday fixes many vulnerabilities that would impact workstations. The Office, Outlook, Windows Codecs, and Media Foundation vulnerabilities should be prioritized for workstation-type devices, meaning any system that is used for email or to access the internet via a browser. This includes multi-user servers that are used as remote desktops for users.
### Windows Spoofing Vulnerability
While listed as Import
Trendmicro
Patch Tuesday: Fixes for Important Vulnerabilities
blogs_trendmicro·2020-08-11·CVSS 7.8
[HIGH] Patch Tuesday: Fixes for Important Vulnerabilities
## Patch Tuesday: Fixes for Important Vulnerabilities
The August batch of Patch Tuesday updates includes 120 updates for the Microsoft suite, with 17 fixes rated as Critical, and the remaining 103 ranked as Important. ZDI disclosed 11 flaws, five of which are rated critical bugs.
By: Trend Micro Aug 11, 2020 Read time: ( words)
Save to Folio
Update on 08/19/2020 09:55AM PHT: Added rules for Trend Micro Deep Security.
The August batch of Patch Tuesday updates includes 120 updates for the Microsoft suite, with 17 fixes rated as Critical, and the remaining 103 ranked as Important. CVE-2020-1380 is a critical Internet Explorer (IE) vulnerability that can be abused for remote code execution (RCE), while CVE-2020-1464 is a Windows 10 security gap that can be used for spoofing. Administrator
Tenable
Microsoft’s August 2020 Patch Tuesday Addresses 120 CVEs (CVE-2020-1337)
blogs_tenable·2020-08-11·CVSS 7.8
[HIGH] Microsoft’s August 2020 Patch Tuesday Addresses 120 CVEs (CVE-2020-1337)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Trendmicro
Patch Tuesday: Fixes for Important Vulnerabilities
blogs_trendmicro·2020-08-11·CVSS 7.8
[HIGH] Patch Tuesday: Fixes for Important Vulnerabilities
Exploits & Vulnerabilities
## Patch Tuesday: Fixes for Important Vulnerabilities
The August batch of Patch Tuesday updates includes 120 updates for the Microsoft suite, with 17 fixes rated as Critical, and the remaining 103 ranked as Important. ZDI disclosed 11 flaws, five of which are rated critical bugs.
By: Trend Micro Aug 11, 2020 Read time: ( words)
Save to Folio
Update on 08/19/2020 09:55AM PHT: Added rules for Trend Micro Deep Security.
The August batch of Patch Tuesday updates includes 120 updates for the Microsoft suite, with 17 fixes rated as Critical, and the remaining 103 ranked as Important. CVE-2020-1380 is a critical Internet Explorer (IE) vulnerability that can be abused for remote code execution (RCE), while CVE-2020-1464 is a Windows 10 security gap that can be used
Krebs
Microsoft Patch Tuesday, August 2020 Edition
blogs_krebs·2020-08-11·CVSS 7.8
CVE-2020-1380 [HIGH] Microsoft Patch Tuesday, August 2020 Edition
Microsoft today released updates to plug at least 120 security holes in its Windows operating systems and supported software, including two newly discovered vulnerabilities that are actively being exploited. Yes, good people of the Windows world, it’s time once again to backup and patch up!
The most concerning of these appears to be CVE-2020-1380, which is a weaknesses in Internet Explorer that could result in system compromise just by browsing with IE to a hacked or malicious website. Microsoft’s advisory says this flaw is currently being exploited in active attacks.
The other flaw enjoying active exploitation is CVE-2020-1464, which is a “spoofing” bug in virtually all supported versions of Windows that allows an attacker to bypass Windows security features and load improperly signed f
Qualys
August 2020 Patch Tuesday – 120 Vulnerabilities, 17 Critical, Media Foundation, Windows Codecs, Workstation, Adobe
blogs_qualys·2020-08-11·CVSS 7.8
[HIGH] August 2020 Patch Tuesday – 120 Vulnerabilities, 17 Critical, Media Foundation, Windows Codecs, Workstation, Adobe
This month’s Microsoft Patch Tuesday addresses 120 vulnerabilities with 17 of them labeled as Critical. The 17 Critical vulnerabilities cover Media Foundation, .NET Framework, Browsers, Scripting Engines, Office, Outlook, Windows Codecs and several other workstation vulnerabilities. Adobe released patches today for Acrobat/Reader, and Lightroom.
## Workstation Patches
Today’s patch Tuesday fixes many vulnerabilities that would impact workstations. The Office, Outlook, Windows Codecs, and Media Foundation vulnerabilities should be prioritized for workstation-type devices, meaning any system that is used for email or to access the internet via a browser. This includes multi-user servers that are used as remote desktops for users.
## Windows Spoofing Vulnerability
While listed as Importan
arXiv
On the Abuse and Detection of Polyglot Files
arxiv_fulltext·2024-07-01
On the Abuse and Detection of Polyglot Files
Notice: This manuscript has been authored [or, co-authored] by UT-Battelle, LLC, under contract DE-AC05-00OR22725 with the US Department of Energy (DOE). The US government retains and the publisher, by accepting the article for publication, acknowledges that the US government retains a nonexclusive, paid-up, irrevocable, worldwide license to publish or reproduce the published form of this manuscript, or allow others to do so, for US government purposes. DOE will provide public access to these results of federally sponsored research in accordance with the DOE Public Access Plan (http://energy.gov/downloads/doe-public-access-plan).
## Abstract
A polyglot is a file that is valid in two or more formats. Polyglot files pose a problem for malware detection systems that route files
to format-sp
https://blog.virustotal.com/2019/01/distribution-of-malicious-jar-appended.htmlhttps://krebsonsecurity.com/2020/08/microsoft-put-off-fixing-zero-day-for-2-years/https://medium.com/%40TalBeerySec/glueball-the-story-of-cve-2020-1464-50091a1f98bdhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1464https://blog.virustotal.com/2019/01/distribution-of-malicious-jar-appended.htmlhttps://krebsonsecurity.com/2020/08/microsoft-put-off-fixing-zero-day-for-2-years/https://medium.com/%40TalBeerySec/glueball-the-story-of-cve-2020-1464-50091a1f98bdhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1464https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-1464
2020-08-17
Published
2021-11-03
Added to CISA KEV
Exploited in the wild