#VU26887 Security Features in MSR JavaScript Cryptography Library - CVE-2020-1026
Published: April 14, 2020
MSR JavaScript Cryptography Library
Microsoft
Description
This vulnerability allows a local user to bypass security rescritions feature.
The vulnerability exists in the MSR JavaScript Cryptography Library due to multiple bugs in the library’s Elliptic Curve Cryptography (ECC) implementation. A remote attacker can gain information about a server’s private ECC key (a key leakage attack) or craft an invalid ECDSA signature that nevertheless passes as valid.