Skip to content
COOEY

EXPOSURES › CVE-2020-0601

CVE-2020-0601

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-0601 ↗
⌖ EXPLOITED IN THE WILD SHAME 78/100 exploited-in-wildunpatched

Microsoft Windows CryptoAPI spoofing vulnerability allowed attackers to use fake code-signing certificates to sign malicious executables and decrypt user connections.

The vulnerability in Crypt32.dll let attackers spoof ECC certificates, enabling them to sign malware as legitimate and conduct man-in-the-middle attacks. DIB orgs must ensure all Windows systems are patched and verify certificate validation processes, as this flaw was actively exploited in the wild.

Shame score — A critical flaw in core Windows cryptography that was actively exploited in the wild, allowing attackers to bypass code-signing trust and decrypt connections.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Microsoft Windows CryptoAPI (Crypt32.dll) contains a spoofing vulnerability in the way it validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source. A successful exploit could also allow the attacker to conduct man-in-the-middle attacks and decrypt confidential information on user connections to the affected software. The vulnerability is also known under the moniker of CurveBall.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Microsoft faced severe fallout for a critical spoofing vulnerability in its CryptoAPI that allowed attackers to use fake code-signing certificates to sign malicious executables, undermining trust in W
cooey ↗ severe-fallout -0.80
Severe condemnation for a critical vulnerability allowing spoofed code-signing certificates to sign malicious executables, undermining trust in Windows code signing.
"An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source."
app.opencve.io ↗ severe-fallout +0.00
Neutral; source is a CVE database listing without commentary on Microsoft's handling.
www.cvefind.com ↗ severe-fallout +0.00
Neutral; source is a CVE database listing without commentary on Microsoft's handling.
support.apple.com ↗ severe-fallout +0.00
Neutral; source is an Apple support page unrelated to Microsoft's CVE-2020-0601.
cvefeed.io ↗ severe-fallout +0.00
Neutral; source is a CISA KEV catalog listing without commentary on Microsoft's handling.
www.realvnc.com ↗ severe-fallout +0.00
Neutral; source is a RealVNC blog unrelated to Microsoft's CVE-2020-0601.
securityonline.info ↗ severe-fallout +0.00
Neutral; source is a CVE Watchtower tool without commentary on Microsoft's handling.
AFFECTED FEDRAMP PRODUCTS · 4
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized