CVE-2023-40012 affects the uthenticode library (versions prior to 2.x), allowing malicious actors to craft seemingly valid "signed" PE files using certificates not intended for code signing, such as SSL certificates, due to a lack of Extended Key Usage (EKU) validation. This vulnerability carries a CVSS score of 7.5 (High), indicating a network-based attack with low complexity and high integrity impact, allowing unauthorized code to appear legitimate. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.0.0CPE matchmatch criteria | cpe:2.3:a:trailofbits:uthenticode:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.