Skip to content
COOEY

EXPOSURES › CVE-2020-1464

CVE-2020-1464

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-1464 ↗
⌖ EXPLOITED IN THE WILD SHAME 75/100 exploited-in-wildunpatched

CVE-2020-1464 is a Windows spoofing vulnerability that allows attackers to bypass security features and load improperly signed files.

This vulnerability enables attackers to load unsigned or improperly signed files by bypassing Windows security controls, posing a significant risk to systems relying on signature validation. DIB organizations must ensure all Windows systems are patched and that file signature validation is strictly enforced to prevent unauthorized code execution. The vulnerability was actively exploited in the wild, highlighting the critical need for timely patching and robust security configurations.

Shame score — A high-severity, actively exploited vulnerability in a widely deployed OS that bypasses core security features, demonstrating significant avoidability and reputational risk.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Microsoft Windows contains a spoofing vulnerability when Windows incorrectly validates file signatures, allowing an attacker to bypass security features and load improperly signed files.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
handled well
cooey ↗ severe-fallout -0.70
handled well
"Microsoft Windows contains a spoofing vulnerability when Windows incorrectly validates file signatures, allowing an attacker to bypass security features and load improperly signed files."
app.opencve.io ↗ severe-fallout -0.70
handled well
"Microsoft CVEs and Security Vulnerabilities - OpenCVE"
www.hipaajournal.com ↗ severe-fallout -0.70
handled well
"Patients Warned About AnMed Communications After Cyberattack Closes 83 Facilities"
www.cvefind.com ↗ severe-fallout -0.70
handled well
"Database CVE, CWE, CISA KEV & Vulnerability Intelligence | CVE Find"
xposedornot.com ↗ severe-fallout -0.70
handled well
"Data Breach Directory & Database: Browse 760+ Known Breaches - XposedOrNot"
watchtowr.com ↗ severe-fallout -0.70
handled well
"watchTowr | Preemptive Exposure Management for AI-Driven Attack Timelines"
AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized