CyberSec.Space Logo
Back to CVE Browser

CVE-2012-0151

Known Exploited (CISA KEV)HIGH
7.8
CVSS Severity Score
EPSS Score81.5980%
EPSS Percentile92.47th
PublishedApr 10, 2012
Last ModifiedApr 22, 2026

Vulnerability Description

The Authenticode Signature Verification function in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly validate the digest of a signed portable executable (PE) file, which allows user-assisted remote attackers to execute arbitrary code via a modified file with additional content, aka "WinVerifyTrust Signature Validation Vulnerability."

Affected Platforms (CPE)

πŸ’»
Microsoft

Windows 7

All versions
πŸ’»
Microsoft

Windows 7

All versions
πŸ’»
Microsoft

Windows Server 2003

All versions
πŸ’»
Microsoft

Windows Server 2008

All versions
πŸ’»
Microsoft

Windows Server 2008

All versions
πŸ’»
Microsoft

Windows Server 2008

= r2
πŸ’»
Microsoft

Windows Server 2008

= r2
πŸ’»
Microsoft

Windows Vista

All versions
πŸ’»
Microsoft

Windows Xp

All versions
πŸ’»
Microsoft

Windows Xp

All versions
πŸ’»
Microsoft

Windows 7

All versions
πŸ’»
Microsoft

Windows Server 2008

All versions
πŸ’»
Microsoft

Windows Server 2008

= r2
πŸ’»
Microsoft

Windows Server 2008

= r2
πŸ’»
Microsoft

Windows Xp

All versions

References & Advisories

Related Vulnerabilities