Evidence dossier
CVE-2013-3900
WinVerifyTrust Signature Validation Vulnerability
Exploited in the wild (CISA KEV since Jan 10, 2022). microsoft reports CVSS 3.1 5.5. Severity assessments differ within at least one CVSS version. EPSS estimates 44.6% exploit likelihood as of Aug 27, 2026.
As of Aug 27, 2026
Normalized restatement
Why is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table and to inform customers that the EnableCertPaddingCheck is available in all currently supported versions of Windows 10 and Windows 11. While the format is different from the original CVE published in 2013, except for clarifications about how to configure the EnableCertPaddingCheck registry value, the information herein remains unchanged from the original text published on December 10, 2013, Microsoft does not plan to enforce the stricter verification behavior as a default functionality on supported releases of Microsoft Windows. This behavior remains available as an opt-in feature via reg key setting, and is available on supported editions of Windows released since December 10, 2013. This includes all currently supported versions of Windows 10 and Windows 11. The supporting code for this reg key was incorporated at the time of release for Windows 10 and Windows 11, so no security update is required; however, the reg key must be set. See the Security Updates table for the list of affected software. Vulnerability Description A remote code execution vulnerability exists in the way that the WinVerifyTrust function handles Windows Authenticode signature verification for portable executable (PE) files. An anonymous attacker could exploit the vulnerability by modifying an existing signed executable file to leverage unverified portions of the file in such a way as to add malicious code to the file without invalidating the signature. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Exploitation of this vulnerability requires that a user or application run or install a specially crafted, signed PE file. An attacker could modify an... See more at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2013-3900
- State
- PUBLISHED
- Published
- Dec 11, 2013
- Updated
- Oct 22, 2025
- Evidence coverage
- 80%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAmicrosoftOriginal evidence ↗
Record text: WinVerifyTrust Signature Validation Vulnerability
Inspect raw assertion
- Field
container- Value
- WinVerifyTrust Signature Validation Vulnerability
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Microsoft WinVerifyTrust function Remote Code Execution
Inspect raw assertion
- Field
observed_exploitation- Value
- Microsoft WinVerifyTrust function Remote Code Execution
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 44.65% probability · 98.67th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.446470000000; percentile 0.986730000000
Assessments differ
Values are shown separately by source and CVSS version.
CISA KEV · catalog date Jan 10, 2022 · first observed Jul 19, 2026
FIRST EPSS · score date Aug 27, 2026 · 98.7th percentile · first observed Aug 27, 2026
microsoft · CVSS 3.1 · first observed Jul 19, 2026 · values shown separately below
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible assertions materially conflict and remain visible side by side.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve conflict
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
WinVerifyTrust Signature Validation Vulnerability
Inspect raw assertion
- Field
container- Value
- WinVerifyTrust Signature Validation Vulnerability
Microsoft WinVerifyTrust function Remote Code Execution
Inspect raw assertion
- Field
observed_exploitation- Value
- Microsoft WinVerifyTrust function Remote Code Execution
44.65% probability · 98.67th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.446470000000; percentile 0.986730000000
Applicability
Cited product scope
Grouped from 1 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
50 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "N/A"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "N/A"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "N/A"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "N/A"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "N/A"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "N/A"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "N/A"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "N/A"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "N/A"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "N/A"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "N/A"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "N/A"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "N/A"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "N/A"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "N/A"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "N/A"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "N/A"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "N/A"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "N/A"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "N/A"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "N/A"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "N/A"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "N/A"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "N/A"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "N/A"}]Affected-product evidence
Accepted scope and product mapping
22 canonical links · 1 source-reported links
vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-026201767813843a6d53867bacde4a55c3035cb868c0a72434012c5e30dab148
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
2682850b-fc2d-4ed5-a99b-0793af78f90b67166172-1e09-4aa8-8197-b84bf6b2c36fvendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-02e254d111ce604757a15650ef469f4f8365d6247da82ce3ac2695c3cfc7dc5f
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
d5c4c0e5-6b44-4163-b6d3-8004f1ca23c3vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-076c7e47c78d9425d54dea0b063ed7cd79e5f9f0bfdb3c9153b8aec4e71a7ad9
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0d6f7e49-f8a1-4abc-9e78-704923bfde13vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-217b1ab3d25f361a639824f86753d418b35aa2a816ee370bb71b5d1dd883d87a
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
33936c10-e04d-4100-b328-f8f3c4dd242f8396acd8-8c7f-4176-b0bd-be071f2114f0vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-25a2932c0bbcb648f7e391c8b9d34c734e5085444c03c1c206b9d4c4baa80b25
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
cace1bdf-90c3-48af-be7a-f416117ff804vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-3fe7da0d567cbba9da3f09deea827ccacd90ac3643fc3e1622f75fb001f24443
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
a7fa26e8-a755-451e-8f2e-b3d99d688335vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-55e90faed8848f3d316cf702d119e83086b6dc5a963d9947a7df1c589f50346d
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
3bd75840-2c80-4a33-a1da-0c0efc9e26ccvendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-5a80416e92fed0cddbb3d4f3840218b448dee11159824ad25a0353da566963fe
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
7e333ee6-3f08-4ad6-9e84-31db5c67a9559a2fcd99-312f-4cd8-987e-92db4ce8e297vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-740fec3e9838b5eabe76ebe27e4d0d7a4cb2e0ef7e13923300d3d0b51e3fce1c
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
5dddd2f9-f97f-4bb0-b0cf-5f555a3f43ebf1f2be0c-9a85-489a-8685-cf3a14084e62vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-7e46de82012029583622f69d79b86bc210b5bd25b8cb3bb4468936702b23c4b0
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
96e54860-f203-411f-804f-74be57c24a38vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-7fe28b5b5b17e017d9554204df059dd619746ffb5c80da87bcbfb1c52720d2f4
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
111f4c45-c8d8-4fb0-b95b-846c5df8fc2216172719-58a9-4318-9be4-ba7afdcd401bvendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-8665879a2f5fe8b8eab868c43d6ace340b95d1f3879639d97ebdf60ef7b49b5f
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
e2325f67-6abb-401a-9792-7dcb0c80183aff6f046d-8d2f-4173-b04c-b55f02374addvendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-9851bd571b8ab08bca589cd73710badfef557d036f0fb7707f694f1c9f597cb4
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
6ec2ca83-4523-4172-933a-a1ea73b32cbevendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-a3084138383423221f61594e86f5b295e5e254acd7ae5284f45e0877a084db43
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
26be247f-ac04-4ec7-a65e-82d12630d6599463a017-8dab-423d-a44c-76e2f94eb673e5e76ee8-4913-4eab-9246-ffcc07a4d281vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-a6295b9daad3ca57ce70751badba5b7fe99229c8a562cc7400e8cfef3daccaee
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
09028e7d-621d-4bb3-abc8-bfb24c52bf1fvendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-bc66b50eed682b3633d0f3a2914725d0a72d6d0d5fece14f566d91bc87448c0b
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
ca5ddb1e-d4aa-4545-9cdc-de4683bc7641vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-d196d31962e613955a91e33e795c22dcfa7bf25173abebaca616a6350cce9ce1
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
4c9e654f-92f8-48af-90f4-ee30e7e321cdvendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-e0c6c3f5c5e95b5b83fbbf719a7de2471749e1ca250bebf19bc7898a937a00ed
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
1c0ee93b-1107-4b48-8623-3ad5f24c1a9avendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-ec10c9f400f23fdf118887f60fe116ffde4adb76dcf118cdd3a7556fd033da3b
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0b951a27-a539-411f-abbf-fdaa94fd6f6evendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-ef5324dcc791e4e872d6c2be0aefa1d7687ca82c3b4ac5d1f72c76cce8395218
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
cd947955-2912-4256-aa3a-e95a103cac9cvendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-f20a05098a41a238f96b56b817d0482887bb39ad40620198bbe05da10ee02ffc
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
8d4bb1ee-f977-4327-82ac-2ebac4235499vendor-01299a5a765aea70faa05f2d06e0c26a5d498fd34553e868d89e8a43b31864db · product-f8c509b6ec25f2a4338a23556be321da5a7c3e8da9f1a4c52f7f15dd0e9a0d2a
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
706ba10e-3019-4b5b-bb1d-e393303ea11daa388854-3a46-4d66-9ba6-65977e133598Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 28
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
21d31354-013d-4172-b01d-21a2babd3d752df59707-a4b0-4548-b817-9dd0398eb9943237bb8f-b830-4eb0-a341-e9f459086e7733a0e736-271e-45fb-9d2e-36507f856e3f4de463fe-906a-49ea-9cf8-afc60237fe504f343a84-7acd-4971-b970-836f13f3ef1e51f939eb-0c7f-4acc-996c-5c61124f08e4530bf805-7d73-49ce-8179-4c897bc787d0596400b7-170b-48ef-a019-6486dd4a4a6763293b72-4da9-464f-90cf-38c75968516764a2201c-bac5-4570-b920-72c84476013e64ff2701-855c-41c3-9cf1-b1f04142317a73b52325-504f-4183-9b6c-e53bf1a277bb78b656b1-4ae0-44ed-8493-b2f4d89400fe7dc60137-51ba-45e6-bc46-e4727d5805027dc94fb7-7c8f-4a82-b426-4e979251e94980d3dd17-b64c-47d1-9c3e-d1957e63c0dc84868517-0a23-474f-9c05-122a3b32be9f94bd7faf-b085-4e9c-a4c7-f2fd863566c296c8d9de-2f51-4d10-9489-72b2d5a0c0f199ac789d-368c-45f6-8e41-c8ab49909a89a57a81aa-3317-49a4-b608-1edaaa35e58ba7e04c46-6c0d-42dd-b90b-6db309b24297b9d035a7-8196-4691-96f6-e75bbf45e1dfc37ee736-c953-4673-a15b-1f11452f77abd575d736-4c26-448d-9066-cad917da855df03fefdd-57f6-450d-b4e5-33c878fbd60ff6c243d8-2b18-4d13-836b-ff49d25aad09Assessments
CVSS by origin
AV:N/AC:H/Au:N/C:C/I:C/A:CCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N/E:U/RL:O/RC:CDirect CVE/CNA normalized decisions
microsoft
CVSS 3.1 · Primary · Original assertion · rank 1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C- Validation
- Valid match
- Recomputed
- 5.5
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
CISA-ADP
CVSS 3.1 · Secondary · Independent enrichment · rank 2
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H- Validation
- Valid match
- Recomputed
- 8.8
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.