#VU18788 Cryptographic issues in Microsoft products
Published: June 13, 2019
SymCrypt
Windows
Windows Server
Microsoft
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to an error when calculating the modular inverse on specific bit patterns with bcryptprimitives!SymCryptFdefModInvGeneric() function when processing X.509 certificates. A remote attacker can supply a specially crafted X.509 certificate to the affected system and trigger denial of service conditions.
Any application that uses the vulnerable library, e.g. antivirus software is susceptible to this issue.