OVERVIEW CVE-2026-39853 is a stack buffer overflow vulnerability in osslsigncode versions prior to 2.12, a tool used for Authenticode signing and verification. The flaw exists in the signature verification paths for PE, MSI, CAB, and script files. During PKCS#7 signature verification, the application fails to validate the length of a digest value before copying it from a parsed SpcIndirectDataContent structure into a fixed 64-byte stack buffer, allowing an attacker to trigger a buffer overflow with a specially crafted malicious signed file. SEVERITY The vulnerability carries a CVSS 3.1 score of 7.8 (HIGH) with a local attack vector, low complexity, no privilege requirements, and user interaction needed. The impact is severe, affecting confidentiality, integrity, and availability with high severity across all three categories. Exploitation occurs when a user attempts to verify a malicious file, potentially enabling stack corruption that could lead to code execution, information disclosure, or denial of service. The EPSS score of 0.00015 indicates lower predictive likelihood of exploitation relative to other vulnerabilities. EXPLOITATION STATUS The vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and shows no active exploitation in the wild. No public exploit code has been reported, and community attention remains minimal, as reflected by the inactive Hot List status. Organizations should update osslsigncode to version 2.12 or later as a preventive measure, though immediate emergency patching is not required based on current threat intelligence.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.12CPE matchmatch criteria | cpe:2.3:a:osslsigncode_project:osslsigncode:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.