A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka 'Windows CryptoAPI Spoofing Vulnerability'.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2020-01-14 23:15
Updated : 2020-01-16 18:15
NVD link : CVE-2020-0601
Mitre link : CVE-2020-0601
JSON object : View
Products Affected
microsoft
- windows_server_2019
- windows_10
- windows_server_2016
CWE
CWE-295
Improper Certificate Validation
