CVE-2020-0601: Microsoft Windows CryptoAPI Spoofing Vulnerability
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka 'Windows CryptoAPI Spoofing Vulnerability'.
Other sources
Microsoft Windows CryptoAPI (Crypt32.dll) contains a spoofing vulnerability in the way it validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source. A successful exploit could also allow the attacker to conduct man-in-the-middle attacks and decrypt confidential information on user connections to the affected software. The vulnerability is also known under the moniker of CurveBall.
— CISA
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-0601?
CVE-2020-0601 is a vulnerability in Microsoft Windows CryptoAPI (Crypt32.dll) that allows for spoofing of Elliptic Curve Cryptography certificates.
How does the CVE-2020-0601 vulnerability work?
An attacker can use a spoofed code-signing certificate to sign a malicious executable, making it appear legitimate by bypassing Windows validation checks.
Who is affected by CVE-2020-0601?
Anyone using Microsoft Windows is potentially affected by CVE-2020-0601.
What is the severity of CVE-2020-0601?
The severity rating of CVE-2020-0601 is high.
How can I mitigate the CVE-2020-0601 vulnerability?
Follow the instructions provided by Microsoft in their security advisory and apply the necessary security updates.