← Back

CVE-2020-0601

nvd nist
Published: Jan 14, 2020Modified: Jun 17, 2026CISA KEV

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Exploitability: 2.8 / Impact: 5.2
Source: NVD

Description

A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka 'Windows CryptoAPI Spoofing Vulnerability'.

Affected (26)

12 products
Windows 10 1507
Windows 10 1607
Windows 10 1709
Windows 10 1803
Windows 10 1809
Windows 10 1903
Windows 10 1909
Windows Server 1803
Windows Server 1903
Windows Server 1909
Windows Server 2016
Windows Server 2019
1 product
Go
Configuration A
24 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
All versions
All versions
Microsoft
All versions
All versions
Microsoft
All versions
All versions
All versions
Microsoft
All versions
All versions
All versions
Microsoft
All versions
All versions
All versions
Microsoft
All versions
All versions
All versions
Microsoft
All versions
All versions
All versions
All versions
All versions
All versions
All versions
All versions
Configuration B
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Golang
From 1.12 to 1.12.16
From 1.13 to 1.13.7
Running on/withPlatform Versions
Microsoft
Windows
All versions

Timeline

No history available yet.