Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-40012

Опубликовано: 09 авг. 2023
Источник: nvd
CVSS3: 5.9
CVSS3: 7.5
EPSS Низкий

Описание

uthenticode is a small cross-platform library for partially verifying Authenticode digital signatures. Versions of uthenticode prior to the 2.x series did not check Extended Key Usages in certificates, in violation of the Authenticode X.509 certificate profile. As a result, a malicious user could produce a "signed" PE file that uthenticode would verify and consider valid using an X.509 certificate that isn't entitled to produce code signatures (e.g., a SSL certificate). By design, uthenticode does not perform full-chain validation. However, the absence of EKU validation was an unintended oversight. The 2.0.0 release series includes EKU checks. There are no workarounds to this vulnerability.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:trailofbits:uthenticode:*:*:*:*:*:*:*:*
Версия до 2.0.0 (исключая)

EPSS

Процентиль: 13%
0.00042
Низкий

5.9 Medium

CVSS3

7.5 High

CVSS3

Дефекты

CWE-325

EPSS

Процентиль: 13%
0.00042
Низкий

5.9 Medium

CVSS3

7.5 High

CVSS3

Дефекты

CWE-325