#VU24254 Spoofing attack in Windows and Windows Server - CVE-2020-0601
Published: January 14, 2020 / Updated: May 7, 2023
Windows
Windows Server
Microsoft
Description
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates. A remote attacker can use a spoofed code-signing certificate to sign a malicious executable, make it appear the file was from a trusted, legitimate source, trick a victim to open it and gain access to sensitive information.