CVE-2020-16922Improper Verification of Cryptographic Signature in Microsoft Windows 10 Version 1507

Severity
5.5MEDIUMNVD
CNA5.3
EPSS
0.5%
top 32.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 16
Latest updateMay 24

Description

A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files. In an attack scenario, an attacker could bypass security features intended to prevent improperly signed files from being loaded. The update addresses the vulnerability by correcting how Windows validates file signatures.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages23 packages

CVEListV5microsoft/windows_76.1.0publication
CVEListV5microsoft/windows_8.16.3.0publication
CVEListV5microsoft/windows_server_20126.2.0publication
CVEListV5microsoft/windows_server_201610.0.0publication
CVEListV5microsoft/windows_server_201910.0.0publication

Patches

🔴Vulnerability Details

2
GHSA
GHSA-pv24-75cx-c5m2: A spoofing vulnerability exists when Windows incorrectly validates file signatures, aka 'Windows Spoofing Vulnerability'2022-05-24
CVEList
Windows Spoofing Vulnerability2020-10-16

📋Vendor Advisories

1
Microsoft
Windows Spoofing Vulnerability2020-10-13
CVE-2020-16922 — Microsoft vulnerability | cvebase