[CVE-2020-1464] Microsoft Windows Spoofing Vulnerability

SecurityDesk
2021.11.03 00:00 조회 7

CISA KEV 정보

취약점명Microsoft Windows Spoofing Vulnerability
설명Microsoft Windows contains a spoofing vulnerability when Windows incorrectly validates file signatures, allowing an attacker to bypass security features and load improperly signed files.
조치사항Apply updates per vendor instructions.
랜섬웨어 캠페인 악용Unknown
CWECWE-347
등록일 (KEV)2021-11-03
조치 기한2022-05-03
추가 참고https://nvd.nist.gov/vuln/detail/CVE-2020-1464

NVD 상세 정보

CVSS v3.1: 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0: 2.1 AV:L/AC:L/Au:N/C:N/I:P/A:N

설명: A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files. In an attack scenario, an attacker could bypass security features intended to prevent improperly signed files from being loaded. The update addresses the vulnerability by correcting how Windows validates file signatures.

CWE: CWE-347 | CWE-347

참조

This product uses the NVD API but is not endorsed or certified by the NVD.



바로 가기

IT 도구 서랍

→ Unix: 2025-01-15T09:30:00
→ 날짜: 1736934600

→ ASCII: ABC
→ 문자: 65 66 67

ASCII 코드표 — 클릭하면 입력란에 추가

DecHex약어설명
DecHex문자
DecHex문자

→ 유니코드: 홍길동
→ 문자: \ud64d\uae38\ub3d9