QID 45535

Date Published: 2022-06-02

QID 45535: Required Certificate Not Present on Host for Windows Qualys Cloud Agent Version 4.8 and Later

Qualys validates windows agent binary files downloaded from the Qualys Cloud Platform is code-signed via Digicert certificates. Beginning May 28, 2021, DigiCert will require the code-signing certificates to be 3072-bit RSA keys or larger. Qualys will be releasing the Windows 4.8 Binary by June 7, 2022. Digital signature validation of Qualys binaries will fail on those assets that do not have the latest 'DigiCert Trusted Root G4' certificate (or later) in the Trusted root certification authority. Qualys strongly recommends installing the certificate by June 6, 2022, to avoid any potential impact.

Affected Version:
Windows Qualys Cloud Agent Version 4.8 and Later

QID Detection Logic
The QID checks if the 'DigiCert Trusted Root G4' certificate is installed or not.

Patch Management jobs and Qualys Windows Cloud Agent upgrades to 4.8 and later will fail.

  • Patch Management - The status of patches will be displayed as "Failed" on the Patch Management UI as the* patch service will fail to validate the digital signature of statusHandler.dll and will log the following error in the log file (C:\ProgramData\Qualys\QualysAgent\Log.txt):
    Error: Patch: Failed to validate the signature of PE binary file...statusHandler.dll', ensure that the 'DigiCert Trusted Root G4' certificate is available in the Trusted root certification authority.
  • Auto Upgrade / Self-Patch of Windows agent - During self-patch, the new version of the binary is downloaded, and the upgrade is initiated. Before initializing, as a part of integrity verification, the binary's digital signature is validated. If the DigiCert Trusted Root G4 certificate is not available, the digital signature validation fails, and the self-patch process is aborted. You will see the following two errors in the log file (C:\ProgramData\Qualys\QualysAgent\Log.txt):
    Error: Setup file "C:\ProgramData\Qualys\QualysAgent\SelfPatch\f959b30c-3bd8-46a2-a67d-f99b96c58f95.exe" did not pass necessary security checks: (win32 code: -2146869243), "The timestamp signature and/or certificate could not be verified or is malformed."
    Error: SelfPatch has failed: (win32 code: -2146869243), "The timestamp signature and/or certificate could not be verified or is malformed."

Solution
Install the required Digicert Certificate i.e. code-signing certificate with 3072-bit RSA keys or larger. For more please refer to Qualys Blog: Qualys Cloud Agent Update: Action needed to update DigiCert Trusted Root G4
Vendor References

CVEs related to QID 45535

Software Advisories
Advisory ID Software Component Link

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report