A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka 'Windows CryptoAPI Spoofing Vulnerability'.
Metrics
Affected Vendors & Products
References
History
Fri, 07 Feb 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
kev
|

Status: PUBLISHED
Assigner: microsoft
Published: 2020-01-14T23:11:20.000Z
Updated: 2025-02-07T15:27:24.883Z
Reserved: 2019-11-04T00:00:00.000Z
Link: CVE-2020-0601

Updated: 2024-08-04T06:11:04.613Z

Status : Modified
Published: 2020-01-14T23:15:30.207
Modified: 2025-02-07T16:15:30.777
Link: CVE-2020-0601

No data.