EXPOSURES › CVE-2020-0601
CVE-2020-0601
HIGH ⌖ ON CISA KEV · EXPLOITEDMicrosoft Windows CryptoAPI spoofing vulnerability allowed attackers to use fake code-signing certificates to sign malicious executables and decrypt user connections.
The vulnerability in Crypt32.dll let attackers spoof ECC certificates, enabling them to sign malware as legitimate and conduct man-in-the-middle attacks. DIB orgs must ensure all Windows systems are patched and verify certificate validation processes, as this flaw was actively exploited in the wild.
Shame score — A critical flaw in core Windows cryptography that was actively exploited in the wild, allowing attackers to bypass code-signing trust and decrypt connections.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows CryptoAPI (Crypt32.dll) contains a spoofing vulnerability in the way it validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source. A successful exploit could also allow the attacker to conduct man-in-the-middle attacks and decrypt confidential information on user connections to the affected software. The vulnerability is also known under the moniker of CurveBall.
"An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source."
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |