CVE Published: 14/01/2020 |
CVE Updated: 04/08/2024 |
CVE Year: 2020 Source: microsoft |
Vendor: Microsoft |
Product: Windows Status : PUBLISHED
CVE-2020-0601 Description
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka \'Windows CryptoAPI Spoofing Vulnerability\'.