Global Supply Chain Cyberattack Exploits Decade-Old Windows Bug with North Korean Links.

1 min read
Source: BleepingComputer
Global Supply Chain Cyberattack Exploits Decade-Old Windows Bug with North Korean Links.
Photo: BleepingComputer
TL;DR

A 10-year-old Windows vulnerability, CVE-2013-3900, is still being exploited in supply chain attacks to make it appear that executables are legitimately signed, with the fix from Microsoft still "opt-in" after all these years. The vulnerability allows adding content to an EXE's authenticode signature section in a signed executable without invalidating the signature. The fix can only be enabled by manually editing the Windows Registry, and it is removed after upgrading to Windows 11, making the device vulnerable again. The flaw has been used in recent attacks, and it should be fixed, even if that inconveniences developers.

Share this article

Want the full story? Read the original reporting

Read on BleepingComputer