CVE-2013-3900 is a remote code execution vulnerability in Microsoft Windows' WinVerifyTrust function, affecting Authenticode signature verification for portable executable (PE) files. An attacker can modify a signed PE file to embed malicious code without invalidating its signature, potentially gaining full system control. With a CVSS score of 8.8 (HIGH), it requires user interaction to run a specially crafted file, but its impact includes complete system compromise. This vulnerability is actively exploited, notably in the 3CX supply chain attack, and despite its age, Microsoft has re-published guidance on an opt-in fix, highlighting its continued relevance and high community attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:x64:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:x86:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:arm64:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:-:*:*:*:*:*:x64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.