CVE-2020-0601, also known as "CurveBall," is a critical spoofing vulnerability in Windows CryptoAPI (Crypt32.dll) affecting how it validates Elliptic Curve Cryptography (ECC) certificates. This flaw allows an attacker to sign malicious executables with spoofed code-signing certificates, making them appear legitimate. With a CVSS score of 8.1 (HIGH), it has a low attack complexity and requires user interaction, but can lead to high confidentiality and integrity impacts. This vulnerability has been actively exploited in the wild, has publicly available proof-of-concept exploit code, and has garnered significant community discussion, as evidenced by its high EPSS score and numerous media mentions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:x64:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1507:-:*:*:*:*:*:x86:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:x64:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1607:-:*:*:*:*:*:x86:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1709:-:*:*:*:*:*:arm64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Windows Crypto API Spoofing Vulnerability (CurveBall)
Jan 15, 2020Windows Crypto API Spoofing Vulnerability (CurveBall)
Jan 15, 2020Windows CryptoAPI Spoofing Vulnerability
Jan 14, 2020This vulnerability is also known as the Windows Crypto API Spoofing Vulnerability. It could be exploited to make malicious executables appear trusted or allow the attacker to conduct man-in-the-middle attacks and decrypt confidential information on user connections to the affected software.