New Search

Windows File Signature Security Feature Bypass Vulnerability - CVE-2019-1163

oval:org.cisecurity:def:6475

A security feature bypass exists when Windows incorrectly validates CAB file signatures. An attacker who successfully exploited this vulnerability could inject code into a CAB file without invalidating the file's signature. To exploit the vulnerability an attacker could modify a signed CAB file and inject malicious code. The attacker could then convince a target user to execute the file. The update addresses the vulnerability by correcting how Windows validates file signatures.

Family:
windows
Status:
ACCEPTED
Platform(s):
  • Microsoft Windows Server 2019
  • Microsoft Windows Server 2016
  • Microsoft Windows 10
Class:
vulnerability
Reference(s):
  • CVE-2019-1163
  • MSRC-CVE-2019-1163
  • KB4512497
  • KB4512517
  • KB4512507
  • KB4512516
  • KB4512501
  • KB4511553
  • KB4512508
Product(s):