PromptRiskDBThreat intelligence atlas

CVE-2020-1464 - Microsoft Windows

AI Vulnerability Context

A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files. In an attack scenario, an attacker could bypass security features intended to prevent improperly signed files from being loaded. The update addresses the vulnerability by correcting how Windows validates file s...

Overview

A source-backed snapshot of this vulnerability.

A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files. In an attack scenario, an attacker could bypass security features intended to prevent improperly signed files from being loaded. The update addresses the vulnerability by correcting how Windows validates file signatures.

CISA KEVyesWhether CISA lists this as exploited.
Techniques0AI attack methods connected to this vulnerability.
Case studies0Examples where this vulnerability is mentioned.

Vulnerability status

How serious this vulnerability is and whether it is known to be exploited.

CISA KEVHIGH
CVE ID
CVE-2020-1464
Vendor/project
Microsoft
Product
Windows
Vulnerability name
Microsoft Windows Spoofing Vulnerability
Date added
2021-11-03
Due date
2022-05-03
Known ransomware campaign use
Unknown
CVSS v3
7.8
CWE-347

Exploit context

What the vulnerability is about.

A spoofing vulnerability exists when Windows incorrectly validates file signatures. An attacker who successfully exploited this vulnerability could bypass security features and load improperly signed files. In an attack scenario, an attacker could bypass security features intended to prevent improperly signed files from being loaded. The update addresses the vulnerability by correcting how Windows validates file signatures.

Source evidence

Original public records and references for this page.

Original source

Original source links

Open the public records and source datasets used for this page.