CVE-2013-3900
Microsoft WinVerifyTrust function Remote Code Execution
- 대응 우선순위
- 최우선
- CVSS
- 8.8
- EPSS
- 44.6% 백분위 98.6% · 2026.06.27 기준
- CISA KEV
- 등록
- 조치 기한
- 2022.07.10
- 공개일
- 2013.12.11
CISA KEV에 등록된 실제 악용 확인 취약점
Why is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table and to inform customers that the EnableCertPaddingCheck is available in all currently supported versions of Windows 10 and Windows 11. While the format is different from the original CVE published in 2013, except for clarifications about how to configure the EnableCertPaddingCheck registry value, the information herein remains unchanged from the original text published on December 10, 2013, Microsoft does not plan to enforce the stricter verifica...
공급사 Microsoft
제품 WinVerifyTrust function
영향 버전 N/A, r2
수정 버전 공식 출처에서 확인 필요
Apply updates per vendor instructions.
조치 기한: 2022.07.10CVSS 벡터 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE CWE-20, CWE-347
KEV 등록일 2022.01.10
랜섬웨어 캠페인 사용 미확인
CISA 비고 https://nvd.nist.gov/vuln/detail/CVE-2013-3900
EPSS 데이터 기준일 2026.06.27