Threat intelligence report · CISA KEV

CVE-2020-0601: Microsoft Windows CryptoAPI Spoofing Vulnerability

Microsoft Windows CryptoAPI (Crypt32.dll) contains a spoofing vulnerability in the way it validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source. A successful exploit could also allow the attacker to conduct man-in-the-middle attacks and decrypt confidential information on user connections to the affected software. The vulnerability is also known under the moniker of CurveBall. Required action: Apply updates per vendor instructions.

· high severity · unattributed attribution

Evidence and provenance

Original source
CISA KEV report ↗
Published
2021-11-03T00:00:00Z
Confidence basis
No actor match
Record ID
14a18e685b84bfac511a

Vulnerabilities

CVE-2020-0601

Affected sectors

technology

Use and citation

Verify the original report before making operational decisions. Cite this permanent page together with the original source, publication date, confidence level, and review status.