PT-2020-3677 · Microsoft+1 · Windows+1
Bernardo Quintero
+2
·
Published
2020-08-11
·
Updated
2026-02-23
·
CVE-2020-1464
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows versions prior to the fixed version
Description
A spoofing vulnerability exists when Windows incorrectly validates file signatures, allowing an attacker to bypass security features and load improperly signed files. In an attack scenario, an attacker could bypass security features intended to prevent improperly signed files from being loaded. The update addresses the vulnerability by correcting how Windows validates file signatures. This issue has been exploited in real-world attacks, with attackers using polyglot files that combine multiple formats to evade detection. These files can be executed as MSI in Windows and as JAR files by the Java runtime environment, allowing them to hide malicious code and bypass antivirus checks.
Recommendations
For Microsoft Windows versions prior to the fixed version, update to the latest version to address the vulnerability by correcting how Windows validates file signatures. As a temporary workaround, consider restricting the use of vulnerable components, such as disabling the execution of polyglot files, until a patch is available. Avoid using files that combine multiple formats, such as MSI and JAR, to minimize the risk of exploitation.
Exploit
Fix
Spoofing
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Java
Windows