How to remediate CVE-2013-3900?

Dhanraj D 6 Reputation points
2024-12-17T11:46:08.0566667+00:00

Hi,

When Microsoft released the remediation steps for this vulnerability, the data type of registry value "EnableCertPaddingCheck" = 1 as REG_SZ and we set this value as "REG_SZ" across all computers. However, I can see that Microsoft changed the data type from "REG_SZ" to "REG_DWORD" on Nov 12th, 2024.

So, my question is if we need to set the value again as "REG_DWORD" or having it as "REG_SZ" as per the initial recommendation is enough to arrest this vulnerability.

Any help would be greatly appreciated on this.

Thanks and Regards,

D.Dhanraj

Windows Server 2019
Windows Server 2019
A Microsoft server operating system that supports enterprise-level management updated to data storage.
3,869 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Hania Lian 20,271 Reputation points Microsoft Vendor
    2024-12-19T03:11:47.7066667+00:00

    Hello,

    Based on the information in the link below, Microsoft recommends that customers test how this change to Authenticode signature verification behaves in their environment before fully implementing it. To enable the Authenticode signature verification improvements, modify the registry to add the EnableCertPaddingCheck value as detailed below. Note that EnableCertPaddingCheck is data type REG_DWORD (an integer value) and not data type string: "EnableCertPaddingCheck"=dword:1.

    CVE-2013-3900 - 安全更新程序指南 - Microsoft - WinVerifyTrust 签名验证漏洞

    Best Regards,

    Hania Lian

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.

    0 comments No comments

  2. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.