← Back to browse · API

CVE-2012-0151

Severity
HIGH
CVSS
7.8
EPSS
0.83534
Risk score
85.44
CISA KEV
Yes
PoC
No
Published
2022-06-08
Modified
2022-06-08
First seen
2026-08-07
Aliases
EUVD-2012-0189, GHSA-99QX-CJ76-9W2H
Products
Microsoft:Windows, n/a:n/a n/a
Sources
euvd EUVD-2012-0189
cisa.gov CVE-2012-0151

Description

The Authenticode Signature Verification function in Microsoft Windows (WinVerifyTrust) does not properly validate the digest of a signed portable executable (PE) file, which allows user-assisted remote attackers to execute code.

References