8.1

CVE-2020-0601

Warnung
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka 'Windows CryptoAPI Spoofing Vulnerability'.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 10 1507 Version - HwPlatform x64
Microsoft ≫ Windows 10 1507 Version - HwPlatform x86
Microsoft ≫ Windows 10 1607 Version - HwPlatform x64
Microsoft ≫ Windows 10 1607 Version - HwPlatform x86
Microsoft ≫ Windows 10 1709 Version - HwPlatform arm64
Microsoft ≫ Windows 10 1709 Version - HwPlatform x64
Microsoft ≫ Windows 10 1709 Version - HwPlatform x86
Microsoft ≫ Windows 10 1803 Version - HwPlatform arm64
Microsoft ≫ Windows 10 1803 Version - HwPlatform x64
Microsoft ≫ Windows 10 1803 Version - HwPlatform x86
Microsoft ≫ Windows 10 1809 HwPlatform arm64
Microsoft ≫ Windows 10 1809 HwPlatform x64
Microsoft ≫ Windows 10 1809 HwPlatform x86
Microsoft ≫ Windows 10 1903 Version - HwPlatform arm64
Microsoft ≫ Windows 10 1903 Version - HwPlatform x64
Microsoft ≫ Windows 10 1903 Version - HwPlatform x86
Microsoft ≫ Windows 10 1909 Version - HwPlatform arm64
Microsoft ≫ Windows 10 1909 Version - HwPlatform x64
Microsoft ≫ Windows 10 1909 Version - HwPlatform x86
Golang ≫ Go Version >= 1.12 < 1.12.16
   Microsoft ≫ Windows Version -
Golang ≫ Go Version >= 1.13 < 1.13.7
   Microsoft ≫ Windows Version -

03.11.2021: CISA Known Exploited Vulnerabilities (KEV) Catalog

Microsoft Windows CryptoAPI Spoofing Vulnerability

Schwachstelle

Microsoft Windows CryptoAPI (Crypt32.dll) contains a spoofing vulnerability in the way it validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source. A successful exploit could also allow the attacker to conduct man-in-the-middle attacks and decrypt confidential information on user connections to the affected software. The vulnerability is also known under the moniker of CurveBall.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 89.44% 0.998
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.1 2.8 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
NIST 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N
CISA-ADP 8.1 2.8 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
CWE-295 Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.

http://packetstormsecurity.com/files/155960/CurveBall-Microsoft-Windows-CryptoAPI-Spoofing-Proof-Of-Concept.html
Third Party Advisory
VDB Entry
http://packetstormsecurity.com/files/155961/CurveBall-Microsoft-Windows-CryptoAPI-Spoofing-Proof-Of-Concept.html
Third Party Advisory
VDB Entry
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0601
Patch
Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-0601
US Government Resource