
PowerShell remediation for CVE-2013-3900 (WinVerifyTrust) / Tenable Plugin 166555 using EnableCertPaddingCheck.
This repository contains a PowerShell remediation + verification script that addresses Tenable/Nessus finding:
The script enforces the WinVerifyTrust certificate padding check by setting:
EnableCertPaddingCheck (DWORD) = 1On 64-bit systems, scanners require the value to be set in both the native registry path and the Wow6432Node (32-bit view) registry path.
CVE-2013-3900 relates to how Windows validates Authenticode signatures using WinVerifyTrust.
If certificate padding checks aren’t enforced, certain crafted signatures may be treated as valid in unsafe scenarios, and vulnerability scanners will flag the host as non-compliant.

✅ Ensures it is run as Administrator
✅ Detects if the OS is 64-bit
✅ Ensures required registry keys exist
✅ Sets EnableCertPaddingCheck to:
1 when $secureEnvironment = $true (secure / recommended)0 when $secureEnvironment = $false (insecure / lab/testing)✅ Prints a clear Before/After table and compliance result
Script location:
scripts/Set-WinVerifyTrustCertPadding.ps1
The script applies the setting to:
HKLM:\Software\Microsoft\Cryptography\Wintrust\ConfigHKLM:\Software\Wow6432Node\Microsoft\Cryptography\Wintrust\Config (64-bit OS)Value enforced:
EnableCertPaddingCheck (DWORD)$secureEnvironment = $true → enforce mitigation (recommended)$secureEnvironment = $false → disable mitigation (lab/testing only).\scripts\Set-WinVerifyTrustCertPadding.ps1
The script verifies the configuration by:
0 on successHigh severity finding present (Plugin 166555 – CVE-2013-3900).
Total findings: 5

High severity finding removed.
Total findings reduced: 5 → 4
