HTTP: Microsoft Windows MSI File Signature Spoofing

This signature detects attempts to exploit a known vulnerability against Microsoft Windows. A successful attack can lead to spoofing of content.

Extended Description

A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files. In an attack scenario, an attacker could bypass security features intended to prevent improperly signed files from being loaded. The update addresses the vulnerability by correcting how Windows validates file signatures.

Affected Products

Microsoft windows_10_1803

References

CVE: CVE-2020-1464

Short Name
HTTP:STC:MICROSOFT-MSI-SPOOFING
Severity
Warning
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2020-1464 File MSI Microsoft Signature Spoofing Windows
Release Date
09/22/2020
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3727
False Positive
Unknown
Vendors

Microsoft

CVSS Score

2.1

Found a potential security threat?