cbcvebase.
CVE-2020-0601
published 2020-01-14

CVE-2020-0601: A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit…

PriorityP190high8.1CVSS 3.1
AVNACLPRNUIRSUCHIHAN
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
89.44%
99.8th percentile
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka 'Windows CryptoAPI Spoofing Vulnerability'.

Affected

39 ranges· showing 25
VendorProductVersion rangeFixed in
golanggo>= 1.12 < 1.12.161.12.16
golanggo>= 1.13 < 1.13.71.13.7
googlechrome_chrome
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows_10_version_1903_for_32-bit_systems
microsoftwindows_10_version_1903_for_arm64-based_systems
microsoftwindows_10_version_1903_for_x64-based_systems
microsoftwindows_10_version_1909_for_32-bit_systems
microsoftwindows_10_version_1909_for_arm64-based_systems
microsoftwindows_10_version_1909_for_x64-based_systems
microsoftwindows_server
microsoftwindows_server
microsoftwindows_server

Detection & IOCsextracted from sources · hover to see the quote

otherMS.Windows.CryptoAPI.ECC.Certificate.Spoofing
  • Qualys QID 91595 can be used to identify vulnerable hosts via authenticated scanning or Cloud Agent; search using QQL: vulnerabilities.vulnerability.cveIds:CVE-2020-0601 and vulnerabilities.vulnerability.qid:91595
  • Focus detection on spoofed ECC code-signing certificates used to sign executables — the certificate will appear to Windows as legitimately chained, bypassing trust checks on signed user-mode processes, HTTPS connections, and signed files/emails.
  • Prioritize monitoring and patching of TLS-terminating infrastructure: web servers, domain controllers, DNS servers, and proxies that perform TLS validation, as these are highest-risk targets for exploitation.
  • Remote exploitation tooling is expected to be rapidly developed and distributed; monitor for new ECC certificate spoofing tools and PoC code referencing 'CurveBall' or 'Chain of Fools'.
  • Public PoCs surfaced within days of disclosure; hunt for executables signed with ECC certificates whose trust chain terminates in a Windows built-in trusted root but whose curve parameters are attacker-controlled.
  • ·Vulnerability affects only Windows 10, Windows Server 2016, and Windows Server 2019 — older platforms (e.g., Windows 7, Windows XP) are not in scope for this CVE despite sharing the crypt32.dll component.
  • ·The Fortinet IPS signature (definitions set 15.757) was released immediately after the Microsoft/NSA announcement; ensure definitions are at or above this version for coverage.
  • ·Qualys Cloud Agent manifest version 2.4.791.3-2 is required to automatically receive QID 91595 for detection; agents below this version will not detect the vulnerability.

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv8.1HIGH
vulncheck8.1HIGH
cisa8.1HIGH
vendor_msrc8.1HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.