Spoofing attack in Microsoft Windows and Windows Server - CVE-2020-0601
Published: January 14, 2020 / Updated: May 7, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates. A remote attacker can use a spoofed code-signing certificate to sign a malicious executable, make it appear the file was from a trusted, legitimate source, trick a victim to open it and gain access to sensitive information.
Affected software
Windows Server
Wyse Windows 10 IoT Enterprise
containerd (Alpine package)
Microsoft Edge
Google Chrome
How to mitigate CVE-2020-0601
Microsoft Edge - update to 79.0.3945.130
Wyse Windows 10 IoT Enterprise - addressed in versions KB-4534271, KB-4534273
Google Chrome - update to 79.0.3945.130
Links to Public Exploits and PoC-codes
- Exploit #9044 - -Awesome-CVE-2020-0601- (2017-0021) (May 7, 2023)
- Exploit #5285 - CVE-2020-0601 (PoC for CVE-2020-0601- Windows CryptoAPI (Crypt32.dll) POC: https://github.com/ollypwn/CurveBall) (April 12, 2021)
- Exploit #5247 - CurveBall-CVE-2020-0601-PoC () (March 30, 2021)
- Exploit #5213 - CVE-2020-0601-spoofkey () (March 14, 2021)
- Exploit #2984 - CVE-2018-20250-WinRAR (June 3, 2020)
- Exploit #2913 - Windows10_Cumulative_Updates_PowerShell (Powershell to patch CVE-2020-0601 . Complete security rollup for Windows 10 1507-1909) (June 3, 2020)
- Exploit #2829 - CurveBall (CVE-2020-0601: Windows CryptoAPI Vulnerability. (CurveBall/ChainOfFools)) (June 3, 2020)
- Exploit #2822 - CurveBall (PoC for CVE-2020-0601- Windows CryptoAPI (Crypt32.dll)) (June 3, 2020)
- Exploit #2831 - gringotts (proof of concept for CVE-2020-0601) (June 3, 2020)
- Exploit #2834 - Awesome-CVE-2020-0601 ( (June 3, 2020)
- Exploit #2837 - CVE-2020-0601 (PoC for CVE-2020-0601- Windows CryptoAPI (Crypt32.dll) POC: https://github.com/ollypwn/CurveBall) (June 3, 2020)
- Exploit #2838 - CurveBallDetection (Resources related to CurveBall (CVE-2020-0601) detection) (June 3, 2020)
- Exploit #2839 - CVE-2020-0601 (Curated list of CVE-2020-0601 resources) (June 3, 2020)
- Exploit #2840 - CurveballCertTool (PoC for CVE-2020-0601 vulnerability (Code Signing)) (June 3, 2020)
- Exploit #2842 - Spoofing attack (June 3, 2020)
- Exploit #2848 - CVE-2020-0601-EXP (这资源是作者复现微软签字证书漏洞CVE-2020-0601,结合相关资源及文章实现。推荐大家结合作者博客,理解ECC算法、Windows验证机制,并尝试自己复现可执行文件签名证书和HTTPS劫持的例子。作为网络安全初学者,自己确实很菜,但希望坚持下去,加油!) (June 3, 2020)
- Exploit #2849 - PoC_CurveBall (PoC for "CurveBall" CVE-2020-0601) (June 3, 2020)
- Exploit #2850 - cve-2020-0601_poc (CVE-2020-0601 proof of concept) (June 3, 2020)
- Exploit #2859 - CVE-2020-0601-spoofkey () (June 3, 2020)
- Exploit #2821 - curveball (CVE-2020-0601 #curveball - Alternative Key Calculator) (June 3, 2020)
- Exploit #2819 - CVE-2020-0601 () (June 3, 2020)
- Exploit #2818 - cve-2020-0601-Perl (Perl version of recently published scripts to build ECC certificates with specific parameters re CVE-2020-0601) (June 3, 2020)
- Exploit #2816 - CVE-2020-0601 () (June 3, 2020)
- Exploit #2815 - CVE-2020-0601 () (June 3, 2020)
- Exploit #2814 - CVE-2020-0601 () (June 3, 2020)
- Exploit #2392 - cve-2020-0601 (Zeek package to detect CVE-2020-0601) (April 7, 2020)
- Exploit #2391 - cve-2020-0601-utils (C++ based utility to check if certificates are trying to exploit CVE-2020-0601) (April 7, 2020)
- Exploit #2231 - Curveball (PoC for CVE-2020-0601 - CryptoAPI exploit) (March 24, 2020)
- Exploit #2220 - meetup-2-curveball (Materials for the second Rijeka secuity meetup. We will be discussing Microsoft cryptoapi vulnerability dubbed CurveBall (CVE-2020-0601)) (March 18, 2020)
- Exploit #2194 - curveball_lua (Repo containing lua scripts and PCAP to find CVE-2020-0601 exploit attempts via network traffic) (March 18, 2020)
- Exploit #280 - CVE-2020-0601 (Remote Code Execution Exploit ) (March 18, 2020)
- Exploit #287 - twoplustwo (Implementing CVE-2020-0601) (March 18, 2020)
- Exploit #286 - chainoffools (A PoC for CVE-2020-0601) (March 18, 2020)
- Exploit #285 - # CVE-2020-0601-spoofkey (March 18, 2020)
- Exploit #284 - badecparams (Proof of Concept for CVE-2020-0601) (March 18, 2020)
- Exploit #283 - CVE-2020-0601 (CurveBall CVE exploitation) (March 18, 2020)
- Exploit #282 - -CVE-2020-0601-ECC---EXPLOIT (CurveBall (CVE-2020-0601) - PoC CVE-2020-0601, or commonly referred to as CurveBall, is a vulnerability in which the signature of certificates using elliptic curve cryptography (ECC) is not correctly verified. Attackers ca (March 18, 2020)
- Exploit #281 - CVE-2020-0601 (A Windows Crypto Exploit) (March 18, 2020)