Microsoft Windows是美国微软(Microsoft)公司的一套个人设备使用的操作系统。 Microsoft Windows WinVerifyTrust 函数处理可移植可执行文件(PE)的Windows Authenticode签名验证的方式中存在输入验证错误漏洞。匿名攻击者可以通过修改经过签名的现有可执行文件以利用文件的未验证部分来利用此漏洞,从而向文件添加恶意代码,而无需使签名无效。成功利用此漏洞的攻击者可以完全控制受影响的系统。攻击者可随后安装程序;查看、更改或删除数据;或者创建拥有完
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Remediation for CVE-2013-3900 | https://github.com/snoopopsec/vulnerability-CVE-2013-3900 | POC Details |
| 2 | Fix WinVerifyTrust Signature Validation Vulnerability, CVE-2013-3900, QID-378332 | https://github.com/CyberCondor/Fix-WinVerifyTrustSignatureValidationVuln | POC Details |
| 3 | None | https://github.com/Securenetology/CVE-2013-3900 | POC Details |
| 4 | Powershell script that checks for cert padding in the Windows Registry and adds it if it does not exist. Meant to resolve the WinTrustVerify Vulnerability. | https://github.com/OtisSymbos/CVE-2013-3900-WinTrustVerify | POC Details |
| 5 | WinVerifyTrust Signature Validation CVE-2013-3900 Mitigation (EnableCertPaddingCheck) | https://github.com/AdenilsonSantos/WinVerifyTrust | POC Details |
| 6 | None | https://github.com/DavidBr27/CVE-2013-3900-Remediation-Script | POC Details |
| 7 | Script to make changes on registry to fix CVE-2013-3900. It comes with an option to undo in case it breaks something on your environment. | https://github.com/piranhap/CVE-2013-3900_Remediation_PowerShell | POC Details |
| 8 | None | https://github.com/pkblanks/Remediating-CVE-2013-3900-EnableCertPaddingCheck- | POC Details |
| 9 | None | https://github.com/malaya-m/cve-2013-3900-remediation-report | POC Details |
| 10 | CVE-2013-3900 WinVerifyTrust Signature | https://github.com/Sabecomoeh/CVE-2013-3900 | POC Details |
| 11 | CVE PoC | https://github.com/PREN0MEN/CVE-2013-3900-PowerShell-PoC | POC Details |
| 12 | None | https://github.com/oukridrig772/-WinVerifyTrust-Signature-Validation-CVE-2013-3900-Mitigation | POC Details |
| 13 | End-to-end remediation of CVE-2013-3900 using PowerShell and Tenable. Demonstrates vulnerability identification, registry hardening, and automated verification in an Azure environment | https://github.com/ksgassama-lab/vulnerability-remediation-cve-2013-3900 | POC Details |
| 14 | PowerShell remediation for CVE-2013-3900 (WinVerifyTrust) / Tenable Plugin 166555 using EnableCertPaddingCheck. | https://github.com/SDimitri05/cve-2013-3900-winverifytrust-mitigation | POC Details |
No public POC found.
Login to generate AI POCЭта информационная заметка содержит увлекательные сведения, которые могут вас удивить! Мы собрали интересные факты, которые сделают вашу жизнь ярче и полнее. Узнайте нечто новое о привычных аспектах повседневности и откройте для себя удивительный мир информации. Получить дополнительные сведения - https://vivod-iz-zapoya-2.ru/
1
1
1
1