Protecting Privacy Build Trust

Protecting Privacy Build Trust
  • Contact Us

Threats & Vulnerabilities

on December 23, 2024 at 8:00 am — CVE-2013-3900 WinVerifyTrust Signature Validation Vulnerability 

Providing further clarification about how to configure the EnableCertPaddingCheck registry value to implement and revert the improvement to authenticode signature verification. Customers who had successfully followed previous guidance do not need to make further changes to their systems. Although Windows treats the EnableCertPaddingCheck value as a DWORD, its actual registry value type does not matter, as long as all these length and data requirements are met. See the **Suggested Actions** section for more information.