HTTP: Microsoft Windows WinVerifyTrust Signature Validation

This signature detects attempts to exploit a known vulnerability against Microsoft Windows Portable Executable (PE) file format. A successful attack can lead to remote code execution.

Extended Description

Microsoft Windows Authenticode Signature Verification is prone to a remote code-execution vulnerability. Attackers can exploit this issue by enticing an unsuspecting victim to run or install a specially modified signed Portable Executable (PE) file. Successful exploits can allow attackers to execute arbitrary code with the privileges of the user running the application. Failed exploit attempts will likely result in denial-of-service conditions.

Affected Products

Avaya messaging_application_server,Avaya meeting_exchange

References

BugTraq: 52868

CVE: CVE-2012-0151

Short Name
HTTP:STC:DL:MS-WIN-VERIFY-TRUST
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2012-0151 Microsoft Signature Validation WinVerifyTrust Windows bid:52868
Release Date
04/09/2012
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Microsoft

Avaya

CVSS Score

9.3

Found a potential security threat?