CVE-2020-0601

CVE Published 2020-01-14
Related CWE(s) CWE-295: Improper Certificate Validation
Related Vendor(s) microsoft, golang
Related Product(s) windows_server_2019, windows_10, windows_server_2016, go
Exploitation Reported (CISA KEV) 2021-11-03
CVSS 3 Base Score 8.1 (HIGH)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka 'Windows CryptoAPI Spoofing Vulnerability'.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References