I got this WinVerifyTrust Signature Validation Vulnerability from a vulnerability scanner in SharePoint servers and other servers and its height Severity, which means it must solve.
Below are details of this vulnerability:
Plugin Name:
- WinVerifyTrust Signature Validation CVE-2013-3900 Mitigation (EnableCertPaddingCheck)
Plugin Output:
- Nessus detected the following potentially insecure registry key configuration:
Software\Microsoft\Cryptography\Wintrust\Config\EnableCertPaddingCheck
Software\Wow6432Node\Microsoft\Cryptography\Wintrust\Config\EnableCertPaddingCheck
From the Plugin Output, it sounds like we need to add this key to the registry, but I can't find the path of this key in the registry.