Microsoft Windows Authenticode Signature Verification Remote Code Execution Vulnerability
Microsoft Windows XP SP2 및 SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2 및 R2 SP1, Windows 7 Gold 및 SP1, Windows 8 Consumer Preview의 Authenticode Signature Verification 함수가 서명된 PE(Portable Executable) 파일의 다이제스트를 올바르게 검증하지 않아, 사용자의 도움이 필요한 원격 공격자가 추가 콘텐츠가 포함되도록 수정된 파일을 통해 임의 코드를 실행할 수 있습니다. 이는 "WinVerifyTrust 서명 검증 취약점"이라고도 합니다.
Microsoft Windows XP SP2 및 SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2 및 R2 SP1, Windows 7 Gold 및 SP1, Windows 8 Consumer Preview의 Authenticode Signature Verification 함수가 서명된 PE(Portable Executable) 파일의 다이제스트를 올바르게 검증하지 않아, 사용자의 도움이 필요한 원격 공격자가 추가 콘텐츠가 포함되도록 수정된 파일을 통해 임의 코드를 실행할 수 있습니다. 이는 "WinVerifyTrust 서명 검증 취약점"이라고도 합니다.
한국어 설명은 영문 원문을 기준으로 제공됩니다. 제품명·버전·보안 식별자는 아래 원문과 함께 확인할 수 있습니다.
영문 원문 보기
The Authenticode Signature Verification function in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly validate the digest of a signed portable executable (PE) file, which allows user-assisted remote attackers to execute arbitrary code via a modified file with additional content, aka "WinVerifyTrust Signature Validation Vulnerability."